lollms-webui Server-Side Request Forgery via /api/proxy
Platform: ParisNeo/lollms-webui
View Exploit PoC ↗Offensive Security Engineer | Security Researcher
Researching Web Security, AI Red Teaming, Protocol Fuzzing and Offensive Engineering.
Initiated self-directed study in assembly logic, reverse engineering, and low-level malware analysis paradigms.
Released SQLMap tamper collections implementing AST queries to bypass Enterprise WAF rules, gaining initial community adoption.
Established Rot Hackers security R&D lab to deliver advanced security tool writeups, building core framework infrastructures.
Architected and deployed Rot Hackers Academy SaaS and mobile applications with end-to-end encrypted logic.
Released WSHawk WebSocket fuzzer, Basilisk red-teaming AI framework, and lectured mobile app security to 50+ students.
Platform: ParisNeo/lollms-webui
View Exploit PoC ↗Platform: ParisNeo/lollms-webui 20.0 Alpha
View Exploit PoC ↗Platform: Ollama < v0.3.14
View Exploit PoC ↗Platform: Ollama < v0.3.14
View Exploit PoC ↗Platform: LiteLLM < v1.51.5
View Exploit PoC ↗Platform: LiteLLM < v1.51.0
View Exploit PoC ↗Platform: LiteLLM < v1.50.0
View Exploit PoC ↗Evolutionary adversarial testing framework automating model jailbreaks and safety boundary discovery via NSGA-II prompt mutations.
Read Case StudyDynamic, interpreted programming language designed with a planning-themed vocabulary and coroutine-grade generators.
Read Case StudyAI model fine-tuned for automated generation of proof-of-concept exploits and multi-platform shellcode.
Read Case StudyCoverage-guided, mutation-based protocol fuzzer for finding vulnerabilities in network protocols and custom binary formats.
Read Case StudyNative, cross-platform reverse engineering framework and desktop workstation for binary analysis, disassembly, and decompilation.
Read Case StudyContext-aware SQL transformation framework for WAF bypass and SQLMap integration using UUID tracking.
Read Case StudyStateful bi-directional WebSocket penetration testing suite automating injection and authorization vulnerability detection.
Read Case StudyLeading offensive R&D and engineering production-grade security artifacts, specializing in high-performance fuzzer development and protocol research.
Delivered a 2.5-hour workshop covering malware development concepts, reverse engineering, exploitation flows, C2 frameworks, OPSEC, and red-team methodology.
Led an intensive 30-day certification program covering full-stack logic, API integration, and database management for mobile environments, mentoring 50+ students through the end-to-end lifecycle.
Delivered a 4-hour comprehensive workshop on modern cybersecurity landscapes, vulnerability research, secure coding practices, and industry career paths.
Focused on offensive security, secure full-stack engineering, AI systems, compiler design, and security tool development through structured, hands-on learning.
Most automated web-application scanners are built around the request/response model of HTTP and do not translate cleanly to WebSocket endpoints, where a single ...
Read Publication ↗Basilisk is an open-source artificial intelligence (AI) red teaming and large language model (LLM) penetration testing framework. It maps the adversarial attack...
Read Publication ↗"The 30-day mobile security and development workshop helped bridge the gap between building logic and understanding runtime exploit paths."
"Demonstrated exceptional technical clarity in detailing how user-mode kernel hooks are bypassed in C2 simulations."
Android posture assessment engine injecting Smali bytecode and intercepting API calls to audit Android 15 applications.
Evolutionary adversarial testing framework automating model jailbreaks and safety boundary discovery via NSGA-II prompt mutations.
Dynamic, interpreted programming language designed with a planning-themed vocabulary and coroutine-grade generators.
Local-first, offline-only password manager encrypting credentials locally with Argon2id and AES-256-GCM.
A finished production-grade tournament management system handling real-time high-concurrency matches and mobile verification protocols.
Comprehensive technical write-ups for 9 weeks of advanced offensive security challenges covering malware analysis, binary patching, and cloud escalation.
AI model fine-tuned for automated generation of proof-of-concept exploits and multi-platform shellcode.
Coverage-guided, mutation-based protocol fuzzer for finding vulnerabilities in network protocols and custom binary formats.
A modern, high-performance cybersecurity learning platform with AI features and integrated payment gateways.
Administrative console managing academy courses, billing logs, and student performance metrics.
React Native learning client featuring end-to-end encrypted local storage and Socket.io interfaces.
Open-source portal hosting security disclosures, coordinated CVE releases, and technical papers.
Native, cross-platform reverse engineering framework and desktop workstation for binary analysis, disassembly, and decompilation.
Context-aware SQL transformation framework for WAF bypass and SQLMap integration using UUID tracking.
Stateful bi-directional WebSocket penetration testing suite automating injection and authorization vulnerability detection.