Log in Join

Research is worth more when it is shared.

Publish findings, explain how you found them, and tell other researchers which programs are actually worth their time. You control what is disclosed, per finding.

Latest findings

View all

Academy

All topics

Learn one vulnerability class at a time, then break it yourself in a hands-on lab that runs in your browser. Free, no setup.

Recent writeups

View all
hamzadzworm.medium.com · 4 days ago

Critical: Account Takeover via Interesting Logic Issue

External writeup by Hamzadzworm (abdelkader mouaz): an account takeover on a passwordless SaaS, chaining an email-uniqueness bypass (a trailing space) with a session-invalidation gap that spared business-mode sessions. The basis for the Nim...

medium.com · 1 week ago

CyberTalents — Evil Rick writeup

The write-up explains the Evil Rick challenge, which involves an insecure Python Pickle deserialization vulnerability. The researcher found hardcoded credentials hidden in the login page’s HTML comments, logged in, and discovered a remember...

CTF CyberTalents 2