Offensive Security Engineer // Penetration Testing, Red Teaming, Research

You can find me on Twitter, GitHub, Intigriti, YesWeHack, and via email at vict0ni at protonmail dot com.

About me

whoami

Contributions

CVEs and Vulnerabilities

Talks and on the media

Pentest Directory

Vulnerability Write-ups

Realme Customer Support Data Leak and Unauth. Access

Roundcube CVE-2024-42008 and CVE-2024-42010 PoC

Chaining XSS and IDOR for Account Takeover

AUDI Database Dump and Session Hijacking

Brocade Fabric OS < 9.1.1 rbash Escape

Security Research

ASCII Smuggling in Google Gemini

On the Hunt for Data Leaks: Elastic(search²)

Oracle Database remote “stealth password brute-force”

Red Teaming

Writing compatible DLLs for DLL Hijacking in C++

Weaponizing LNK Files in Offensive Operations