CASE—001
jxs in dev
Passive JS capture & analysis pipeline. mitmproxy → js-beautify → LinkFinder → mantra → SQLite → React Flow. Next: AI-driven sink/source analysis to replace static pattern matching.
FIELD LOG — 0xnhsec
Independent Web Application Security Researcher
Self-taught since 20 Apr 2025. Loving in Research and couriousiting in Learning.
"Lost in the layers of abstraction, where the patterns define reality and the filter dictates what survives." - 0xnhsec
01 / PROJECTS
CASE—001
Passive JS capture & analysis pipeline. mitmproxy → js-beautify → LinkFinder → mantra → SQLite → React Flow. Next: AI-driven sink/source analysis to replace static pattern matching.
CASE—002
Concentrated Attack Surface Methodology — strategic framework for web exploitation & bug bounty hunting. Read methodology
CASE—003
WAF blind spot research tool with XSS mutation engine, canary injection, and blind XSS tracking via ngrok.
CASE—004
Intentionally vulnerable C2C marketplace lab. Phased roadmap: XSS, BAC, IDOR, Business Logic, File Upload, SSRF, XXE.
02 / WRITEUPS
HUB—01
Lab-by-lab breakdown across SQLi, XSS, BAC, JWT, OAuth, Auth, DOM, Race Conditions, and more — grouped by vulnerability class.
HUB—02
13 challenges solved: pwn, reverse engineering, crypto, ICS/OT, and misc/blockchain — full PoC walkthroughs.