Posts by jomynn

@jomynn

Jomy nn

Thailand jomynn.com Joined August 2026
300 Points12 Badges0 Connections0 Followers16 Following

Posts by jomynn

jomynn in Videos 1 min read
One file path. No form, no captured traffic, no automated finding anywhere in the pipeline. Here's the full story of a real CWE-611https://cwe.mitre.org/data/definitions/611.html XML External Entity vulnerability — the first bug in this series where ...
post-cover-26138
jomynn in Videos 5 min read
A full walkthrough of finding, proving, and reporting a real SSRF bug with a deterministic rule engine, a live form-based exploit, an attempted and explained automated probe, and a fully offline local LLM — no cloud AI anywhere in the pipeline. tags:...
post-cover-25968
jomynn in Videos 3 min read
The bug Here's the route from a small Express demo app scan-target-demo-apps/apps/06-path-traversalhttps://github.com/sendwavehub/scan-target-demo-apps: app.get'/files', req, res => { const name = req.query.name; const filePath = path.joindocs...
post-cover-25748
jomynn in Videos 3 min read
One tainted variable. One shell on the host. Here's the full story of a real CWE-78https://cwe.mitre.org/data/definitions/78.html OS Command Injection vulnerability, from the moment a rule engine flags it to a disclosure-ready report — all running lo...
post-cover-25539
jomynn in Videos 3 min read
> ⚠️ Educational / authorized testing only. Everything below targets a local, deliberately vulnerable training application, not a live system. Never run these techniques against anything you don't own or don't have explicit written authorization to t...
post-cover-25416
jomynn in Videos 2 min read
Most IDOR write-ups stop at "change the ID in the URL and you get someone else's data." That's the easy part. The part that actually matters — proving it rigorously, ruling out the boring explanation, and turning it into a report someone can act on —...
post-cover-25293
jomynn in Videos 3 min read
How AiSec Studio pipes every scan through parser → rule engine → knowledge graph before a local LLM ever sees it — and why that order matters. 60-second Auto Scan demo included. Most "AI-powered" security scanners work the same way under the hood: ...
post-cover-25125
jomynn in Videos 3 min read
https://youtu.be/GknBmsqaFk4 The bug Here's a login endpoint from a small Express demo app scan-target-demo-apps/apps/01-sql-injectionhttps://github.com/sendwavehub/scan-target-demo-apps: app.post'/login', req, res => { const { username = '', pa...
post-cover-25124
chevron_left

Latest Jobs

View all jobs →