Pentester / red teamer / bug bounty hunter / researcher.

You can find me on Twitter, GitHub, Intigriti, YesWeHack, and via email at vict0ni at protonmail dot com.

Research

CVEs and Vulnerabilities

Talks and on the media

Blog

Weaponizing LNK Files in Offensive Operations

Roundcube CVE-2024-42008 and CVE-2024-42010 PoC

On the hunt for data leaks: Elastic(search²)

Chaining XSS and IDOR for Complete Account Compromise

Brocade Fabric OS < 9.1.1 rbash Escape to read System Files

Oracle Database remote “stealth password brute-force”

Bypassing the IPinfo API