My personal notes on pentesting web apps, source code review etc.
-
Updated
Dec 4, 2024
My personal notes on pentesting web apps, source code review etc.
Do-It-Yourself Infosec labs, create your own lab and exploit it!
Burp Suite Pro extension for finding insecure UUIDs (predictable, reversible, or MAC-based) in HTTP flows
Field notes for offensive security, browser-first where it works. DevTools, web and API testing, OWASP Top 10 2025, RCE, source code review, Active Directory, cloud, containers, pivoting and privilege escalation. Plain language, MIT licensed.
Syntropy Security's comprehensive security audit of the Online Banking Management System v1.0. Our assessment concludes that the application in its current state poses unacceptable risk to the organization. We identified five (5) critical security failures that would cause catastrophic financial loss and total operational paralysis if deployed.
Practice source code review through real-world vulnerable snippets with detailed solutions and security explanations.
AI-powered source code security audit tool built with React & TypeScript — automatically scan, review, and detect vulnerabilities, security flaws, and coding risks using ChatGPT-driven static analysis.
To associate your repository with the source-code-review topic, visit your repo's landing page and select "manage topics."