Authentication vs Authorization: From Internal Mechanics to Deep Testing

A technical deep dive into authentication state, session and token lifecycles, authorization models, access-control enforcement, IDOR/BOLA, privilege escalation, and practical testing methodology.
Read more →

HTB TwoMillion Walkthrough

HTB TwoMillion Walkthrough
A technical walkthrough of Hack The Box TwoMillion, covering invite-code generation, authenticated API enumeration, broken authorization, command injection, credential reuse, and CVE-2023-0386.
Read more →

Hello, World

The first post on this blog
Read more →