Published onMarch 27, 2026Bypassing WAF Method Blocks with X-HTTP-Method-OverrideCyber-SecurityBug-BountyWAF-BypassWeb-SecurityHow an OPTIONS request with x-http-method-override can bypass blocked GET/POST methods, and how defenders can shut it down
Published onMarch 23, 2026Bypassing Imperva Incapsula WAF with a Cookie Jar OverflowCyber-SecurityBug-BountyWAF-BypassWeb-SecurityHow a cookie jar overflow attack allowed me to completely bypass Imperva Incapsula's reese84 token validation
Published onOctober 2, 2025Wiz Cloud Security Championship Challenge 4Cyber-SecurityBug-BountyCTFFuzzingA walkthrough on my solution for Wiz's Needle in a Haystack CTF
Published onSeptember 16, 2025Wiz Cloud Security Championship Challenge 3AzureCyber-SecurityBug-BountyCTFA walkthrough on my solution for Wiz's Breaking The Barriers CTF