root.sec
Breaking into web applications, hunting vulnerabilities, and building security tools. Documenting the journey along the way.
* Bug Bounty Hunting
* Vulnerability Research
* Security Tooling
Bug Hunting & Ethical Hacking
Breaking web apps, finding vulnerabilities, and documenting the hunt
CTF Writeups
Walkthroughs of HackTheBox and TryHackMe machines with methodology breakdowns.
Bug Bounty
Real-world vulnerability discoveries, hunting techniques, and responsible disclosure stories.
Technical Deep Dives
In-depth analysis of attack vectors, security tools, and exploitation techniques.
Recent Writeups
HackTheBox – DevArea
Detailed exploitation walkthrough for HackTheBox DevArea machine, covering Apache CXF SSRF (CVE-2022-46364), Hoverfly middleware RCE, and world-writable bash privilege escalation.
mKingdom
A detailed walkthrough for the mKingdom machine on TryHackMe. This write-up covers CMS password guessing, achieving initial access via PHP file upload, pivoting through multiple users using discovered credentials and tokens, and finally escalating to root through a writable /etc/hosts file and a malicious cron script.
Plant Photography
A comprehensive deep-dive into the Plant Photography room from TryHackMe. This write-up covers the exploitation of SSRF to achieve Local File Inclusion, extracting sensitive system data, and reconstructing the Werkzeug debugger PIN to gain full Remote Code Execution via an unauthenticated console.
HackTheBox – CCTV
Exploitation walkthrough for HackTheBox CCTV machine, covering ZoneMinder SQL injection, motionEye credential theft, and CVE-2025-60787 RCE for root access.
Featured Projects
LUNA (Neural Assistant)
Real-time, voice-to-voice holographic AI companion designed natively for Linux desktop systems. Powered by the Google Gemini Live API.
SafeClick
Chrome extension that analyzes websites in real time to determine their trust score. Detects phishing sites using threat intelligence databases and heuristic logic.
Ready to secure your assets?
Let's collaborate on security research, penetration testing, or just chat about the latest vulnerabilities.