JMJasveer MaanCyber Security Enthusiast
Menu

Write-ups

Research notes, labs, and walkthroughs.

20 write-upsPage 1 of 2

locked

HTB - MakeSense

Hack The Box write-up with exploitation notes and lessons learned.

Admin Endpoints Hiding in a JS Bundle: How a Missing Auth Check Turned Into Cross-Tenant OAuth Secret Disclosure

Missing server-side access control on an admin API surface let a non-admin token enumerate every OAuth M2M integration and pull live client secrets across unrelated tenants.

locked

HTB - Paperwork

Hack The Box write-up with exploitation notes and lessons learned.

locked

HTB - Bedside

Hack The Box write-up with exploitation notes and lessons learned.

locked

HTB - SmartHire

Hack The Box write-up with exploitation notes and lessons learned.

locked

HTB - Helix

Hack The Box notes focused on practical attack path thinking.

Exploiting React Server Components RCE (React2Shell – CVE-2025-55182)

Request-level exploitation notes for React Server Components RCE testing.

Fixing “Illegal Server Name” Error in Burp Suite Caused by Underscores in Domain Names

Troubleshooting notes for Burp Suite DNS handling and match-replace behavior.

LLM Assisted Source Code Review Using FalconEye

Using LLM-assisted workflows to accelerate source code review and vulnerability discovery.

Using Burp Suite Professional Without Installing It on a Client VDI (via SSH & EC2)

A practical SSH and EC2 workflow for proxying client VDI traffic into Burp Suite Pro.

Child-to-Parent Domain Escalation: Lessons Learned from Kerberos ETYPE Pitfalls

Active Directory escalation notes from Kerberos ticketing and hash-dump edge cases.

Exfiltrating Data via DNS in a Restricted Environment

DNS exfiltration testing in restricted network conditions.