~/research/notes

Writing

Research notes, exploit development, mobile security labs and reverse engineering work.

17 posts

2026

  1. ios 17 min read

    Jailbreaking the iPhone 3GS from Scratch, Part 3: Bypassing the Boot Chain

    Jailbreaking the iPhone 3GS from Scratch, Part 3: Bypassing the Boot Chain Note: I am always learning. This series is a study project, not a definitive guide, and I will certainly …

  2. ios 28 min read

    Jailbreaking the iPhone 3GS from Scratch, Part 2: Reverse Engineering the BootROM

    Jailbreaking the iPhone 3GS from Scratch, Part 2: Reverse Engineering the BootROM Note: I am always learning. This series is a study project, not a definitive guide, and I will …

  3. ios 20 min read

    Jailbreaking the iPhone 3GS from Scratch, Part 1: initial access

    Jailbreaking the iPhone 3GS from Scratch, Part 1: initial access Note: I am always learning. This series is a study project, not a definitive guide, and I will certainly make …

  4. writeup 7 min read

    phpIPAM 1.7.4 - Second Order SQL Injection via subnetOrdering

    Second Order SQL Injection in phpIPAM 1.7.4 (CVE-2026-4189) Back in 2022, I found a SQL injection in phpIPAM 1.4.4 (CVE-2022-23046) via the BGP mapping search feature. That was a …

2025

  1. mobile 4 min read

    Runner Mobile Hacking Labs

    In this challenge, you’ll be working with a fictitious app called Run Time, which tracks your steps while running. Your objective is to bypass the app’s protections, inject a …

  2. mobile 26 min read

    Captain No Hook Mobile Hacking Labs

    Introduction The Captain No Hooks lab provides an in-depth exploration of iOS RASP (Runtime Application Self-Protection) defenses. This comprehensive guide focuses on how we can …

  3. mobile 4 min read

    Time Trap Mobile Hacking Labs

    Introduction In this challenge, you will explore the vulnerabilities in an internally used application named Time Trap, focusing on Command Injection. Time Trap is a fictional …

  4. mobile 6 min read

    Gotham Times Mobile Hacking Labs

    Introduction The Gotham Times lab provides an in-depth exploration of iOS webviews and their security implications. This comprehensive guide focuses on how vulnerabilities in …

  5. mobile 3 min read

    Flipcoin Wallet Mobile Hacking Lab

    Flipcoin Wallet CTF - SQL Injection Challenge In this CTF challenge, I'll explore a SQL Injection vulnerability ( Client Side) in the Flipcoin Wallet iOS app. I'll walk you through …

  6. mobile 6 min read

    Breaking Flutter’s RSA Encryption: Reverse Engineering and Hooking Techniques

    In my previous post Bypassing MTLS in Flutter, I discussed how MTLS is generaly implemented in the Flutter framework. Depending on how an application is developed, exposing …

2024

  1. writeup 6 min read

    Nasa Path Traversal and XSS (waf bypass)

    Exploit Path Traversal and XSS in NASA Subdomains In this post, I’ll share my journey of discovering two vulnerabilities on NASA subdomains (Just 4 fun). With a bit of luck (and a …

  2. mobile 7 min read

    Bypass MTLS Flutter

    Overview In this blog post, we'll tackle: bypassing mTLS with Flutter due to common mistake ( ¯\(ツ)/¯ ) from developers. Before we continue.. into the specifics, it's essential to …

  3. mobile 10 min read

    Decrypt WhatsApp Msgs Android (Investigator)

    Overview In this blog post, we'll tackle a compelling challenge: decrypting WhatsApp messages. However, before we dive into the solution, it's crucial to grasp some foundational …

2023

  1. writeup 4 min read

    Template Injection Kitctf

    In this blog post, we will explore a specific template injection vulnerability discovered in a CTF (Capture The Flag) challenge from kitctf. We will delve into the details of the …

  2. writeup 6 min read

    PHPIPAM CVE

    TL;DR This write up is about a SQL injection which I found 4 days after another researcher reported it :/, however, because of the fact that I haven’t found any write ups or …

2022

  1. ctf 3 min read

    Reversing Nim Binary With Radare

    This write up explains how i solved the challenge proposed by CakeCTF2022. The challenge was to get the flag in a binary made with the Nim (https://nim-lang.org/) program language. …

  2. writeup 4 min read

    iOS Anti-Tampers Bypass

    Hi everyone, in this blog i'm going to explain a little bit of my journey to solve a iOS challenge proposed by @as0ler. The Challenge can be found at the following link: …