web app security and pentesting — learning through labs, writeups, and building tools.
- SQLi, IDOR, SSRF, XSS, and path traversal
- offensive Python and HTTP internals
- proxies, raw sockets, and web security labs
- PortSwigger Academy — web security lab writeups
- TryHackMe Writeups — notes and walkthroughs
- labs — DVWA, WebGoat, Metasploitable 2, and more
- pentools — Python security tools
- http-proxy-lab — a HTTP proxy built from raw sockets
- dir-brute — a directory brute-forcer and crawler
DOM XSS, API security, JWTs, business-logic bugs, and better pentesting methodology.
appsec and pentesting internships.
