Blog Archive
All Posts
Single-Packet Race Condition: Sub-Millisecond Web Exploitation
Wed May 27 2026How the single-packet attack technique eliminates network jitter to exploit sub-millisecond race conditions in web applications — and how CVE-2024-58248 in nopCommerce was exploited using Burp Suite.
Category: Security ResearchConfusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server
Wed May 27 2026How Orange Tsai's Confusion Attacks exploit URL decoding inconsistencies across Apache modules to chain ACL bypass, SSRF, and unauthenticated RCE — #1 web hacking technique of 2024.
Category: Security ResearchCVE-2025-69460 – Simple Image Gallery 1.0 - Remote Code Execution (Unauthenticated)
Wed Jan 21 2026CVE-2025-69460: Unauthenticated Remote Code Execution (RCE) vulnerability in Simple Image Gallery 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.
Category: Security ResearchCVE-2025-69457 – Responsive Tourism Website 3.1 - Remote Code Execution (Unauthenticated)
Wed Jan 21 2026CVE-2025-69457: Unauthenticated Remote Code Execution (RCE) vulnerability in Responsive Tourism Website 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.
Category: Security ResearchCVE-2023-38890 – Online Shopping Portal 3.1 Remote Code Execution
Wed Jan 21 2026CVE-2023-38890: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Online Shopping Portal 3.1. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.
Category: Security ResearchCVE-2025-69458 – Movie Rating System 1.0 - SQL Injection to RCE (Unauthenticated)
Wed Jan 21 2026CVE-2025-69458: Unauthenticated SQL Injection to Remote Code Execution (RCE) vulnerability in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.
Category: Security ResearchCVE-2025-69459 – Movie Rating System 1.0 - Broken Access Control
Wed Jan 21 2026CVE-2025-69459: Broken Access Control vulnerability allowing Admin Account Creation in Movie Rating System 1.0. Zero-day discovery and exploit by Tağmaç 'Tagoletta'. Full writeup with PoC exploit code.
Category: Security ResearchBuilding a Compact Cyber Security Home Lab with Proxmox
Mon Dec 08 2025Turning a modest notebook into a powerhouse running Tor, Exploit Dev, Docker, and OPNsense environments.
Category: ResearchTraffic Offense Management System 1.0 - Remote Code Execution (Unauthenticated)
Wed Aug 18 2021Zero-Day Discovery & Exploit Development: unauthenticated SQL Injection to RCE in Traffic Offense Management System 1.0. Full writeup with PoC exploit code by Tağmaç 'Tagoletta'.
Category: Security Research