Blog
Notes on APIs, automation, and security.
Technical posts on reverse-engineering, security research, automation patterns, and the day-to-day of solo engineering work.
Blog
Technical posts on reverse-engineering, security research, automation patterns, and the day-to-day of solo engineering work.
A quick checklist for reading HTTP response headers and spotting security misconfigurations before you even look at the response body.
DevTools shows you everything, which is the problem. Here's how I filter signal from noise when reverse-engineering a web application's API.