I'm qwez, an information security person. Most of my time goes into offensive web work, binary exploitation, and the occasional forensics engagement when something interesting lands on my desk.
Web — SSRF, deserialisation, prototype pollution, auth bypass, logic flaws. Anything where the app trusts the user more than it should. Comfortable with Burp, ffuf, sqlmap, and rolling custom Python when the off-the-shelf tools run out.
PWN — userspace heap, kernel attack surface, modern mitigations. Tracking how CFI, MTE, and PAC reshape the primitives we use. Daily drivers: gdb + gef, pwntools, ROPgadget, one_gadget.
Forensics — memory, disk, network. Volatility, Autopsy, Wireshark, plaso. The slow, careful side of the field.
Languages I write in: Python (daily), C (comfortable), Haskell (learning), Rust (learning).
Currently rebuilding aemu_postoffice in Haskell to see how a typed, STM-based architecture holds up against the original TypeScript + C++ servers. Wire-protocol compatibility is the goal; still a work in progress.
Open an issue on any of my repos if you want to talk.


