Security Research
Technical research & experiments
Application security, reverse engineering, cloud, API and AI security research.
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.
Latest Research
12 articlesHTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.
Understanding HTTP Request Smuggling
A methodology for analyzing parser inconsistencies between HTTP components.
Getting Started With Frida
An introduction to runtime instrumentation for authorized application research.
Practical API Authorization Testing
A structured approach to testing object and function authorization in APIs.
Understanding Prompt Injection
A security-oriented introduction to prompt injection in LLM applications.
AWS S3 Security Misconfigurations
A practical framework for reviewing S3 access controls and exposure.
Network Reconnaissance Methodology
A structured approach to mapping an authorized network assessment.
Building a Practical SAST Pipeline
How to structure static analysis in a development pipeline.
Static Analysis IPA file
Static Analysis IPA file using strings,
Get the IPA file
Get the IPA file from different resources
SSL Kill Switch 2
Bypass SSL Pinning iOS Applications
Flutter App SSL Pinning Bypass Using ReFlutter
A simple workflow to extract, merge, patch, sign, and install a Flutter APK for security testing.