Security insights & write-ups

Pentesting stories, techniques, and lessons learned along the way.

Pentesting 2026-02-27 8 min read

Vulnerability Scan vs. Penetration Test: Why the Cheaper Option Could Cost You More

They're not the same service. Why pentests cost what they cost, what you're risking when you give someone access to your systems, and why cutting corners is the most expensive decision.

Read more
Pentesting 2026-02-26 7 min read

How to Choose a Penetration Testing Company: A Practical Guide

What to look for in a pentester, which certifications actually matter, what a quality report includes, and how to avoid paying for an empty deliverable.

Read more
OSINT 2026-02-23 6 min read

The Internet Never Forgets: How Archived Data Becomes a Security Risk

You deleted it. You moved on. But the Wayback Machine didn't. Learn how archived URLs and cached pages become real attack vectors.

Read more
Career 2026-02-05 5 min read

My Hack The Box CWEE Review & Experience

A detailed review of the CWEE exam: study tips, the 10-day exam experience, mindset advice, and why debugging is your best friend.

Read more
Web Security 2026-01-27 4 min read

Bypassing Nginx ACLs in Python Applications

How a trailing tab character can bypass Nginx regex ACLs when Python's .strip() normalizes the URL after the security check has already passed.

Read more
Pentesting 2025-08-31 3 min read

How One Google Search Led to a Critical Vulnerability

A critical vulnerability found in seconds using OSINT and Google dorking. An exposed API key with no usage limits that could have caused massive financial damage.

Read more