INDEPENDENT SECURITY RESEARCH

Finding the cracks
between trust boundaries.

Android, mobile applications, WebViews, deep links, native bridges, web applications, APIs, reverse engineering, and reproducible PoCs.

01Android / Mobile

WebViews, deep links, native bridges and client-side attack surfaces.

02Web / API

Endpoints, authentication, authorization and application trust boundaries.

03Proof over theory

Practical research with clean, reproducible proof-of-concepts.

FIELD NOTES

Latest write-ups

View all →

RESEARCH

Notes & articles

View all →
research@womp:~
$ whoami
womp — independent security researcher

$ focus --current
android · webviews · api · reverse-engineering · web

$ methodology
"practical research + reproducible PoCs"