we break things
so others don't have to.

web pentesting · reverse engineering · infrastructure audit
operators
web pentester · infra auditor
web app pentesting infra audit OWASP OSINT wifi sniffing network recon Rust Python Shell

Специализируется на тестировании инфраструктуры — сети, сервисы, периметр. Находит то, что логи не замечают.

reverse engineer · web researcher
reverse engineering web recon wifi sniffing cryptography OSINT Chrome extensions Python JavaScript Shell C

Смотрит на сайт глазами атакующего снаружи. Разбирает клиентскую логику и ломает то, что должно было быть скрыто.

scope
[INF]
Infra Audit
Периметр, порты, сервисы, SSL, DNS, misconfig
[WEB]
Web Pentest
OWASP Top 10, auth bypass, IDOR, injections, logic flaws
[REV]
Reverse Eng.
JS deobfuscation, binary analysis, client-side secrets
[RPT]
Reporting
Детальные отчёты с PoC и рекомендациями по патчу
recon sample
webpie@archlinux:~
webpie@archlinux:~$ nmap -sV -sC --open target.example.com
Starting Nmap 7.94 ... PORT STATE SERVICE VERSION 80/tcp open http nginx 1.24.0 443/tcp open ssl/http nginx 8080/tcp open http Apache Tomcat 9.0.71 ← outdated
webpie@archlinux:~$ nuclei -u https://target.example.com -t exposures/
[critical] CVE-2023-XXXX — exposed admin panel /manager/html [info] X-Frame-Options header missing [info] Content-Security-Policy not set
webpie@archlinux:~$
связь
webpie · email w3bpie@gmail.com webpie · telegram @webp1e marpel · email marpelskiy98@cocaine.ninja marpel · telegram @localhost54