seggewiss

Learning IT security in public — eJPT, CPTS, OSCP, and what actually happens along the way.

Posts

Two Critical Bugs in Shopware's App System

I found two critical bugs in Shopware 6. One is a sandbox escape in App Scripts, one is a stored SQL injection through custom entities. Both break the same trust boundary: the App. Reported, fixed, credited, and now public. No exploit details.

The Blind Spot My Training Gave Me

First box after the eJPT and I walked past the vulnerability that solves it. Not because it was hidden, but because two months of labs taught me it was not worth looking at. About what your practice material quietly teaches you.

eJPT: Passed

First certificate on the eJPT → CPTS → OSCP path is done. What worked for me while preparing — labs before videos, and a small browser extension I wrote to remove the hints. No exam details, there will not be any.

Reading a Netmask Without Guessing

I got a subnet wrong in a pivoting lab because I guessed the CIDR instead of reading it from the netmask. Here is the real math, and the two mistakes that made it worse.

Why I'm Learning Pentesting in Public

The plan: eJPT, then CPTS, then OSCP — written down while I go, not polished afterwards, on the way to freelancing.