Father / Hacker / Geek / Bug Bounty Hunter

Protecting businesses by day

Hunting bugsby night

People often ask how to start hacking, what to learn first, and which programming languages matter if you want to become truly professional in this field.

My answer is always the same: there is no default path. You have to feel the methods, stay relentlessly curious, and question every single bit that appears on your screen.

SAME CURIOSITY. DIFFERENT PERSPECTIVE.

CURIOSITY DRIVES SECURITY

Mindset

I break things to understand how they work. Curiosity, intuition and a never-ending desire to learn fuel everything I do.

“The moment you stop being curious is the moment you stop growing.”

OFFENSIVE THINKING. REAL IMPACT.

What I Do

At Hackrate, I lead ethical hacking engagements that help companies uncover weaknesses before attackers do. After hours, I keep digging—hunting bugs, playing CTFs, dissecting attack surfaces, reverse engineering systems, and figuring out how things fail.

  • Security Advisory
  • Bug Bounty
  • CTF
  • Reverse Engineering
  • Offensive Security
  • Security Research

PUBLICLY TRACKED SECURITY RESEARCH

CVEs

2026 PUBLISHED

CVE-2026-89023

ThemeAtelier Domain For Sale — Missing Authorization via REST API

Unauthenticated attackers could access and manipulate protected REST API resources in Domain For Sale versions before 3.5.2, including retrieving stored offers, deleting offers by numeric identifier, and accessing dashboard statistics containing sensitive bidder and business data.

CWE-862 CVSS v4.0 8.8 Unauthenticated Affected < 3.5.2 Published 2026-09-14
2021 FIXED

CVE-2021-3813

Chatwoot — Improper Privilege Management / Inbox conversation exposure

A user without collaborator access to an Inbox could retrieve conversations by supplying an enumerable inbox_id. The issue crossed a clear authorization boundary and exposed data from inboxes the user was not assigned to.

Reported 2021-09-06 Validated 2021-09-17 Fix released 2022-02-04
2023 DISCLOSED

CVE-2023-6583

WordPress plugin — Directory Traversal

A directory traversal issue identified during WordPress plugin research and tracked publicly as CVE-2023-6583.

WordPress ecosystem Directory traversal Public CVE record

RESEARCH NOTES / ADVISORIES / DISCLOSURES

Publications

A trimmed archive of the security research worth keeping from the previous site. No CTF writeups, no Hungarian archive — only public research, disclosures and technical observations.

03 AUG2026
SECURITY ADVISORY HIGH IMPACT

Unauthenticated Access to Sensitive Offer Data in Domain For Sale 3.5.1

The WordPress plugin exposed sensitive REST API endpoints without effective authentication or authorization. An unauthenticated attacker could retrieve stored offer records, delete arbitrary offers by numeric ID, and access administrative business statistics.

WordPressBroken Access ControlCWE-862Unauthenticated
Technical snapshot

Affected product: Domain For Sale – Sell Domains with Landing Pages, Offers & Inquiries

Affected: 3.5.1 · Fixed: 3.5.2

Exposed endpoints:

GET /wp-json/domain-for-sale/v1/offers DELETE /wp-json/domain-for-sale/v1/offers/{id} GET /wp-json/domain-for-sale/v1/dashboard?period=all_time

The disclosed records could include names, email addresses, phone numbers, offer amounts, message contents, verification tokens, IP addresses, browser/device information and WordPress-linked user details.

Timeline: reproduced and reported 2026-07-23 · vendor acknowledged 2026-07-23 · fixed 2026-07-24 · advisory published 2026-08-03 · CVE requested 2026-08-03.

29 JUL2026
RESEARCH WORDPRESS

Five Days Inside the WordPress Plugin Attack Surface

A data-driven look at an automated WordPress plugin audit sprint: 402 software targets, 417 completed audits, 748 candidate findings and 37,924 known vulnerability records used for duplicate comparison.

748candidate findings
98medium+
29high severity
416unauth / low-priv reachable
Key patterns

The strongest repeated themes were not exotic primitives, but small trust mistakes: sanitization confused with security, nonces treated as permissions, public routes reusing privileged assumptions, and renderers trusting attacker-controlled structure.

The core triage question was always the same: who can reach the primitive, what boundary does it cross, and what impact can be demonstrated?

01 JUN2023
DISCLOSURE MEDIUM · 6.5

Partial Local File Inclusion / Directory Traversal in CollectiveAccess

The GetDirectoryLevel functionality accepted attacker-controlled path input. An authenticated user could escape the application directory and enumerate operating-system level directories, even though arbitrary file contents were not directly readable.

CollectiveAccessPath TraversalAuthenticatedCVSS 6.5
Disclosure timeline

Reported 2023-05-25 · validated 2023-05-26 · fixed 2023-05-26.

The original rating was Medium with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.

31 AUG2021
DISCLOSURE XSS

Stored XSS in reNgine

A stored cross-site scripting issue was reported in the reNgine reconnaissance scanner and subsequently fixed upstream.

reNgineStored XSSDisclosure
2020ZOOM
VULNERABILITY RESEARCH MEDIUM · 4.0

Zoom Cloud Meetings Windows Client — Memory Heap Inspection

Research against Zoom Windows Client 4.6.11 showed that email addresses and plaintext passwords could remain recoverable from process memory. The later client behavior reduced exposure to periods where the user was logged in.

Windows ClientMemoryCredential ExposureCVSS 4.0
Disclosure notes

The issue required local capability to create or inspect process memory dumps. Contact attempts were made on 2020-04-14, 2020-05-02 and 2020-07-04. A CVE was requested on 2020-07-05.

LET'S BUILD A MORE SECURE TOMORROW.

Contact

Available for collaboration, advisory and security-focused work.