whoami
Sakado
Chief OuinOuin Officer
the actual boss.
Cybersecurity engineer. I spend my days on web applications, which mostly means finding out that the authentication flow was held together by one poorly named boolean. The rest of the time I'm doing crypto challenges and losing arguments with my own maths.
This blog is where I dump the long version: writeups, notes on things I broke, and the occasional postmortem of a bug that turned out to be me. No newsletters, no cookie banner, no "we value your privacy."
FOCUS
Web
Auth, sessions, access control, and the long tail of bugs that look harmless alone and considerably less harmless chained together. Source review when I can get it, black box when I can't.
Crypto
Attacking implementations rather than primitives: reused nonces, homemade padding, and the entropy that turned out to be a timestamp. Mostly for fun, occasionally for profit.
FIELD NOTES
Currently
Staring at a request that shouldn't have worked.
Weapon of choice
Burp, Python, and an unreasonable amount of patience.
Playground
Root-Me, CTFs, and whatever I'm allowed to touch.
Known bugs
Drinks too much coffee. Status: won't fix.