Breaking the first-run boundary
Two independently discovered flaws in GoAnywhere MFT turned an initialization route into unauthenticated administrative access.
Selected vulnerability research, contest work, and coordinated disclosures. Each entry separates personal findings, co-research, and team outcomes.
Two independently discovered flaws in GoAnywhere MFT turned an initialization route into unauthenticated administrative access.
An XML-comment interpretation conflict could bind an attacker's signed external identity to an existing authentik account.
An unauthenticated SSRF and improper log neutralization in a-blog cms could be combined to hijack an administrative session.
Missing authentication exposed privileged functionality; operating-system command injection turned that access into remote code execution.
Map how identity, parsing, and state move between components.
Turn odd behavior into the smallest reproducible security claim.
Give maintainers evidence they can validate, fix, and communicate.