Blog
Writing on application security, WAF engineering, malware analysis, and security engineering.
#appsec
#cloudflare
#credential-theft
#cve
#ddos
#exploit-analysis
#http2
#ntlm
#protocol
#red-team
#uri-handler
#windows
-
CVE-2023-44487: HTTP/2 Rapid Reset — The DDoS That Broke Records and Rewrote Assumptions
Deep-dive into CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability that generated 398 million requests per second and forced every major cloud provider to patch their stacks simultaneously.
#cve#ddos#http2#cloudflare#appsec#protocol#exploit-analysis -
CVE-2026-33829 & The Unpatched Sibling: How Windows URI Handlers Keep Leaking Your NTLMv2 Hashes
Deep-dive into the Snipping Tool NTLM leak, its unpatched search: URI handler twin, the decade-long history of Windows coercing NTLM authentication, and why Microsoft's servicing policy creates systematic blind spots.
#cve#ntlm#windows#credential-theft#red-team#appsec#uri-handler