How to pwn a website and take over any account
How a broken password-reset flow exposed recovery secrets to unauthenticated users and turned account recovery into a complete account-takeover primitive.
INDEPENDENT SECURITY RESEARCH
Android, mobile applications, WebViews, deep links, native bridges, web applications, APIs, reverse engineering, and reproducible PoCs.
WebViews, deep links, native bridges and client-side attack surfaces.
Endpoints, authentication, authorization and application trust boundaries.
Practical research with clean, reproducible proof-of-concepts.
No active research session
FIELD NOTES
How a broken password-reset flow exposed recovery secrets to unauthenticated users and turned account recovery into a complete account-takeover primitive.
How a shared CloudFront cache exposed an HttpOnly session credential embedded in server-rendered Next.js responses.
RESEARCH
We found BlueHammer exploit logic inside a malware sample — another sign that CVE-2026-33825 had moved from public research into real-world offensive tooling.
A short field note on why WebView-to-native interfaces deserve careful threat modeling.
$ whoami
womp — independent security researcher
$ focus --current
android · webviews · api · reverse-engineering · web
$ methodology
"practical research + reproducible PoCs"