Auditing an MCP server: 2 flaws that keep showing up in production
Command injection and path traversal in remote MCP servers: the vulnerable file and line, a curl PoC for each one, and the fix, with your own lab to practice safely.
Offensive Security Expert · Ethical Hacker
First-hand research, tooling and writeups. I write what I test.
Research lines2026
published posts per topic
latest updates
Command injection and path traversal in remote MCP servers: the vulnerable file and line, a curl PoC for each one, and the fix, with your own lab to practice safely.
AI applied to bug bounty is no longer futurism: it speeds up recon, prioritises findings and drafts reports. Real use cases, hard limits and concrete risks.
I presented El Kraken at Ekoparty 2023: an automated recon tool that speeds up bug bounty while cutting VPS costs using GitHub Actions and DigitalOcean.
How to spin up ephemeral scanning infrastructure with GitHub Actions and DigitalOcean, and ship the results to an ELK stack for real-time metrics and visibility.