/root/jankesec :: pentest + vuln research

Notes from the unauthorized-looking side of authorized research.

Field logs for web application pentesting, vulnerability research, exploitability boundaries, and practical validation without the conference gloss.

Latest Drops

Write-ups, methodology notes, and vulnerability analysis from the lab.

View all

Operating Areas

Precise, repeatable notes for work that happens below the glossy layer.

Projects

Open-source tools and research code.

GitHub →
Swift

evilcorp-ios

Intentionally vulnerable iOS application for mobile security training — 30 challenges across OWASP MASVS categories

⭐ 0
Go

ghostlink

Covert C2 channel over legitimate platforms — stealthy command and control for authorized red team ops

⭐ 0 MIT
Go

driftnet2

Network traffic interception and analysis toolkit — passive recon and protocol inspection

⭐ 0

Latest CVEs

Vulnerabilities discovered during authorized security research.

View all
SQL Injection (SQLi) — Akıllı Ticaret E-Commerce Website
SQL Injection (SQLi) — Dolusoft Omaspot
Cleartext Transmission of Sensitive Information — Dolusoft Omaspot
Index

Browse the archive by lane

Stay Updated

New research, straight to your feed.

Subscribe via RSS for vulnerability research, pentest methodology, and technical write-ups. Longer-form analysis also available on Substack.