00x8r41nr07inbraindump.0x8r41nr07.xyz·Aug 26 · 5 min readEvery Break-In Has a Three-Act StructurePart 8 of an ongoing series. Read Part 1 here. "You really need to study past attacks to know what to look for." I wrote that in my journal this week, halfway through Linux Security Monitoring, half-f00
00x8r41nr07inbraindump.0x8r41nr07.xyz·Aug 24 · 6 min readI Used to Hunt Audiences. Now I Hunt Attackers.Part 7 of an ongoing series. Start with part 1 here. It happened on a Tuesday, somewhere between a DNS tunneling exercise and my third cup of coffee. I was staring at a network log — VPN entries, fire00
00x8r41nr07inbraindump.0x8r41nr07.xyz·Aug 23 · 3 min readWhere Things Stand (And Where They're Going)Part 6 of an ongoing series. Start from Part 1 here. A year ago, June 2025, the MacBook Air arrived and everything felt alien. Here's what a year looks like: three certifications passed. Hundreds of h10
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 16 · 2 min readApplication Mapping: Web Security FoundationStrategic Rule: Exploitation without reconnaissance is guesswork. Comprehensive mapping reveals the complete attack surface, exposing high-impact vulnerabilities that automated scanners may overlook. 11Z
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 15 · 6 min readEncoding in Web ApplicationsWeb applications move data constantly—through URLs, form fields, cookies, headers, and API payloads. The catch: many transport mechanisms (especially URLs and HTML) are text-oriented, while real input11Z
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 14 · 8 min readClient-Side Web Security EssentialsModern web apps aren’t just “pages in a browser”—they’re interactive systems where the client (browser) and the server continuously exchange data and decisions. If you’re learning web application secu10
HHugoinhugovalters.hashnode.dev·Jul 27 · 4 min readProxy vs VPN: Stop Confusing Privacy with SecurityI recently had a conversation with a developer who was convinced their home network was “fully secured” because they had a “VPN” extension active in Chrome. They were browsing a sensitive site in one 00
HHugoinhugovalters.hashnode.dev·Jul 27 · 2 min readHow to Protect Your Homelab and API with a Free Self-Hosted WAF (SafeLine Docker Install)Why I Stopped Trusting Cloudflare Alone My site recently crossed 5,000 daily visitors. Sounds like a celebration. What it actually means is that the volume of garbage hitting my server — automated sca00
AFAeon Flex / Splicer Scorninchaincoder.hashnode.dev·Jun 27 · 7 min readI Mapped an Entire Building’s RF Footprint Without Walking Inside. Here’s How.It started with a bet. A friend — let’s call him Marcus — works in physical security. He runs RF site surveys for corporate clients. The kind of work where you walk into a building with a spectrum ana00
SCSamihan Chatterjeeinsamihan.hashnode.dev·Mar 26 · 6 min readProject OBLITERATUS OBLITERATUS OBLITERATUS is a specialized open-source toolkit designed for "abliteration"—the surgical identification and removal of refusal behaviors in large language models (LLMs) without the need f00