← all writing

Starting shellcat

This is where the write-ups live now.

I’ve spent long enough keeping notes in private markdown files that never see daylight. The good ones deserve to be read — not for clout, but because the methodology is the part that transfers. Anyone can copy a payload. What’s worth writing down is the reasoning: why I looked at that endpoint, what made the response smell wrong, how a couple of “informational” quirks stacked into something a program actually paid for.

What goes here

  • Write-ups — real chains from authorized programs, sanitized, with reproducible steps.
  • Notes — short primitives and gadgets worth remembering.
  • Method — how the bug was found, not just what it was.

What doesn’t

No theoretical bugs. No “could potentially.” No naming targets that haven’t shipped a fix. If a post is here, there was a proof of concept and there was a resolution. That’s the whole bar.

PC or GTFO. Proof of concept or it doesn’t exist.

More soon. The queue is full.

shellcat @shellcat
Security researcher. PC or GTFO.