max@raa.ms
:
~
/
posts
$
about
posts
projects
Posts
2025
Exposed CI/CD Secrets from Compromised GitHub Action
17 Mar
2023
Hunting weak DKIM keys for fun, profit and RedBull
26 Nov
Exploiting Gmail's ARC implementation flaws
25 Nov
Stored XSS on 5.000+ Dutch websites
28 Jan
2022
Hacking the Dutch Government
22 Jun
2021
Finding a 4 million ticket data leak
29 Jul
2020
Case Study: Softaculous Soft Binary
5 Nov
Root Privilege Escalation on a Shared Webserver
20 May
CTF Writeups