xsspresso
xsspresso

A personal log of my offensive security journey, including CTF writeups, projects, blog posts, certifications, and more. Built as a way to learn, share, reflect, and keep improving over time.

color220°

CTF Writeups

CTF solutions, events and more.

View all

Projects

Personal projects for learning.

View all
Vulnerable Blog App

Vulnerable Blog App

Full-stack intentionally vulnerable application built for CCNY EE I7700 Penetration Test & Ethical Hacking. Covers the full attacker kill chain from initial access to root via XSS, node-serialize deserialization RCE, and privilege escalation through a world-writable script run by root.

From the Blog

Latest CVEs, certifications, tools, anything security related.

View all