Starting shellcat
This is where the write-ups live now.
I’ve spent long enough keeping notes in private markdown files that never see daylight. The good ones deserve to be read — not for clout, but because the methodology is the part that transfers. Anyone can copy a payload. What’s worth writing down is the reasoning: why I looked at that endpoint, what made the response smell wrong, how a couple of “informational” quirks stacked into something a program actually paid for.
What goes here
- Write-ups — real chains from authorized programs, sanitized, with reproducible steps.
- Notes — short primitives and gadgets worth remembering.
- Method — how the bug was found, not just what it was.
What doesn’t
No theoretical bugs. No “could potentially.” No naming targets that haven’t shipped a fix. If a post is here, there was a proof of concept and there was a resolution. That’s the whole bar.
PC or GTFO. Proof of concept or it doesn’t exist.
More soon. The queue is full.