/ˈbar/ • nouns
Security Researcher and CTF Player with @Try4gain. Mostly into reverse engineering, forensics, web exploitation, and Linux.
Besides security shit, I enjoy playing a pixel art games and watching anime.
cve-2026-48067 came from a scope mismatch in filament AttachAction and AssociateAction
cve-2026-47755 let a low-privileged authenticated user pull another client credentials and totp secrets in itflow
how i reported six shopper cves spanning authorization bypass, privilege escalation, race conditions, idor, and xss
authenticated sharp users could download unrelated laravel storage objects through the generic download endpoint
one vulnerability. multiple targets. multiple certificates.
upsolved it tho :p