mitsec

Writeups

Research & exploitation notes

Full chains, dead ends included. Everything here comes from disclosed or authorized work.

exploit2026-07-12

Chaining Email Enumeration to Full DB Dump

A low-severity user enumeration primitive escalated into an unauthenticated database dump through a chained IDOR and a leaky export endpoint.

11 min readread →
web2026-06-02

DOM Clobbering + Cross-Origin Exploit Chain

Turning a harmless HTML injection into account takeover by clobbering a script-loader config object and pivoting through a permissive postMessage handler.

9 min readread →
mobile2026-05-18

Android Pentesting Without Root — FridHunter

Gadget injection workflow on Termux: repacking, 8-layer pinning bypass, and automated secret extraction on non-rooted devices.

14 min readread →
exploit2026-04-27

CVE-2025-55182 — Next.js RSC Deserialization to RCE

Walkthrough of the React Server Components request path, the UTF-16LE WAF bypass, and a reliable exploitation primitive.

12 min readread →
api2026-03-15

SOAP APIs Are Still a Goldmine

WSDL harvesting, operation enumeration and auth-boundary testing on legacy telecom stacks.

8 min readread →
recon2026-02-08

Recon at Scale: subfinder → httpx → custom

The stdin/JSONL pipeline convention behind every tool I ship, and why zero-dependency Python wins on remote boxes.

7 min readread →
↑↓ navigate↵ openesc close