// Writing
The Best Exploits Are Boring
Every writeup that gets shared around is a novel zero-day in a parser nobody's heard of. Every real engagement I've run ends the same way: a reused credential, an over-permissioned service account, and a route nobody thought to close. None of it is exciting. All of it works.
The primitives that keep showing up
- Credentials reused across "isolated" environments that share a directory service somewhere upstream.
- Service accounts scoped for convenience during setup and never revisited.
- Internal endpoints exposed because a load balancer rule was copy-pasted from a public-facing one.
- Trust boundaries that exist on a diagram but not in an ACL.
Individually, none of these are a finding worth a CVE. Chained, they're a full compromise. And each link in the chain leaves evidence you can read without any scanner: a pinned certificate that expired, a cert issued by an internal CA nobody recognizes, a fingerprint that doesn't match the one in the runbook. The X.509 Certificate Decoder dumps a PEM cert's subject, issuer, SANs, and fingerprints in your browser — paste the chain from the load balancer nobody re-checked and read exactly what it trusts.
Why this matters more than the zero-day narrative
If your threat model is "sophisticated novel exploit," you'll spend your budget on the wrong things — bug bounty triage for exotic memory corruption, while the actual path in is a jump box with a shared password from 2019.
The craft in offensive security isn't finding the impossible bug. It's noticing that three unremarkable, individually-accepted risks compose into one that isn't. Defense has to think the same way: audit the chain, not just the links.
The attacker doesn't need a zero-day. They need you to have stopped looking at the boring stuff.
// Read next — more in Offensive security
How to Build an Agent Audit Trail Before You Need It
The provider's copy expires on their clock. Build the trail you own — context snapshots, provenance, a config hash, into storage the agent can't rewrite.
9 min read
Your AI Agent Has No Audit Trail
When an agent incident needs explaining, the evidence is already gone — context evaporates, and the provider's copy expires on a clock you don't set.
8 min read
CSP Nonces and the Same-Origin Policy Solve Different Problems
A CSP nonce and the same-origin policy both show up in the same sentence about XSS, but they guard different boundaries — one says which script on this page is allowed to run, the other says which origin is allowed to read what. Confusing them leaves one of the two unguarded.
6 min read