sondt / nosiaht

security researcher ยท bug hunter ยท ctf player

โ†“

I hunt real bugs in real targets, break down IoT firmware, write reproducible research, and keep my CTF brain sharp with RE & Pwn.

about
Bug Hunting
Clear reports with affected versions, impact, logs, and payloads. Less hype, more proof.
IoT Security
Firmware trees, web handlers, command wrappers, default configs, and every weird path between them.
CTF Player
Model the binary, find the primitive, build the payload with exact offsets.
research
Firmware Mapping
Extract images, trace init scripts, map web roots, find writable paths.
Embedded Web
Auth boundaries, command wrappers, template paths, upload flows.
Reverse Engineering
Function clusters, string refs, parser behavior, state machines.
toolkit

Linux ยท Python ยท C ยท Burp Suite ยท Ghidra ยท IDA ยท Binwalk ยท pwndbg ยท Firmware ยท IoT Web ยท ROP

principles
  • Show artifact, target version, surface first.
  • Separate observed facts from guesses.
  • Keep commands, offsets, payloads exact.
  • Explain impact without hype.
  • Small reproducible samples > long explanations.
contact
published cves (100+) โ†’
=^..^=