Zapho | A Security Journal

$whoami

I break authentication for a living, and trust for fun.

Application Security Engineer by daylight, currently embedded deep in a fintech's attack surface; Web, Mobile, API, wherever the logic bends. I've spent this stretch chasing the gaps between what a system checks and what it assumes: BOLA chains that shouldn't exist, MFA flows that fold under a forged event, sessions that outlive their welcome, races won by whoever hits send first.

This isn't a portfolio. It's a field log of my craft. Every post here is pulled from something I actually broke; an endpoint that trusted a client too much, a token that never expired, a "secure" channel that wasn't. I write it down because the exploit is only half the lesson; the other half is why nobody caught it first.

Toolchain: Caido, Burp Suite, Frida, Objection, jadx, apktool.