My name is Vlad. I am an ethical hacker, pentester and a CTF player.
I create pentest tools and CTF tasks.
- Automatic SSTI detection tool with interactive interface
- Situational extra plugins for SSTImap
- A simple transparent HTTP proxy using Flask
- Looking for RCE in Safe Template Engines (details will be published later)
- Writeup about developing payloads for CVE-2026-46640
- New Code Injection and SSTI techniques
- Learning IoT hacking and looking for vulns in my IP camera
- RCE in Mustache for Ruby using built-in method access
- RCE via Code Injection in Pybars3 and Pybars4 template engines
- QR-based device sharing credentials leak in v380 Pro IP camera app
- Root shell accessible over UART with hardcoded password in v380 camera
- Plaintext credentials in the filesystem of the v380 camera





