-
SQL injection, from first principles
Why untrusted input concatenated into a query is still one of the most common bugs on the internet โ and how to actually reason about it instead of memorizing payloads.
-
Building a home lab for pentesting practice
A minimal, isolated setup for practicing recon and exploitation legally against your own targets โ hypervisor, network segmentation, and a starter VM list.
-
OSINT recon: notes from the field
A practical checklist for the passive recon phase of an authorized engagement โ what to look for and where, before you touch anything.