offensive security researcher. i hunt hostile-input bugs - the kind that pop when a security tool eats attacker-controlled data - and i run responsible disclosure campaigns against whoever ships them.
- π tool audits - i point scanners, frameworks and agents at themselves. recent reports: Tenable, Rapid7, Greenbone
- π₯ CVE PoCs - weaponized proof-of-concepts in my spare time (see below)
- βοΈ cloud red team - AWS / GCP attack paths, role juggling and privilege-escalation mazes
- π» hardware bench - Flipper Zero + ESP32 counter-surveillance: hunting Flock/ALPR cameras and rogue BLE trackers
- π languages - Python first, Ruby for module dev
score so far: 2 fixed (1 with a bounty π) - 1 partially fixed - 4 ghosted π» - 3 refused - 1 pending public writeup
these are feeding a security conference talk.
| CVE | PoC |
|---|---|
| CVE-2026-19626 | POC-CVE-2026-19626 |
| CVE-2026-19679 | POC-CVE-2026-19679 |
| CVE-2026-19681 | POC-CVE-2026-19681 |
more in the oven as disclosures clear.
| CVE | Info |
|---|---|
| NOCVE-2009 | Addonics NAS Adapter NASU2FW41 bts.cgi DoS |
| NOCVE-2009 | Addonics NAS Adapter NASU2FW41 nas.cgi DoS |
| CVE-2009-4753 | Addonics NAS Adapter NASU2FW41 FTP based DoS |
| NOCVE-2009 | HP Deskjet 6840 firmware XF1M131A reflected XSS |
| NOCVE-2010 | CiviCRM 3.1 < Beta 5 - Multiple Cross-Site Scripting Vulnerabilities |
| NOCVE-2010 | dotProject 2.1.3 XSS / Improper Permissions |
| NOCVE-2017 June, 01 | Torch router authentication bypass, clear text credentials, and more. CERT VU#118167. |
| CVE-2017-6526 | dnaLIMS unauthenticated RCE |
| CVE-2017-6527 | dnaLIMS directory traversal |
| CVE-2017-6528 | dnaLIMS plaintext password storage |
| CVE-2017-6529 | dnaLIMS session hijacking |
| CVE-2022-34876 | VICIdial authenticated SQLi |
| CVE-2022-34877 | VICIdial authenticated SQLi |
| CVE-2022-34878 | VICIdial authenticated SQLi |
| CVE-2022-34879 | VICIdial reflected XSS |
| CVE-2024-48530 | eSoft Planner DoS |
| CVE-2024-48531 | eSoft Planner reflected XSS |
| CVE-2024-48533 | eSoft Planner account enumeration |
| CVE-2024-48534 | eSoft Planner reflected XSS |
| CVE-2024-48535 | eSoft Planner stored XSS |
| CVE-2024-48536 | eSoft Planner incorrect access control |
https://www.exploit-db.com/?author=1611
full list of external repos (not mine) that i've sent PRs to:
593 upstream PRs to 25 external repos (repos i don't own), plus 25 collab PRs in friends' forks
metasploit module work usually starts in friends' forks before it lands upstream:





