Hadrien Chauder
CVE writeups and web exploitation research, SSRF and account-takeover chains included.
External articles, talks, and tools I keep coming back to. Filter by tag.
CVE writeups and web exploitation research, SSRF and account-takeover chains included.
Yoan's corner: hacking writeups on one side, Provence food on the other.
Google's free O'Reilly book on building systems that are secure and stay up. The SRE security bible.
Bug bounty guides and notes on AI-assisted testing, plus a weekly newsletter.
Linux x86-64 syscall table: numbers, registers, and man-page links. The page I keep open while writing shellcode.
The by-hackers-for-hackers bug bounty podcast. Technical episodes on real web bugs and workflow.
A big French DevSecOps knowledge base: hardening, supply chain, IaC, CI/CD, the lot.
Brown's interactive fork of the Rust book, with quizzes and a better ownership chapter.
The hacker zine. Deep exploitation and reversing articles, still going.
Mizu's blog: web exploitation, CTF writeups, and disclosed CVEs.
Community security knowledge base. Pentest cheatsheets and exploitation tutorials, EN and FR.
Laluka's blog. SSRF/XXE/RCE chains and offensive-security writeups.
A catalog of malware evasion and anti-analysis techniques, with code and YARA rules.
The ProxyLogon/ProxyShell-tier web exploitation writeups.
Long-running RE community forum on packers, protectors, and anti-tamper.
xorpd's wordless assembly puzzle book. One snippet at a time.
A hands-on RE course built around analyzing one unknown binary, by xorpd.
Where a lot of indie security courses (ReversingHero included) are sold.
PortSwigger's research hub. Where new web attack classes get named.
A talk on using LLMs as taint-reasoners for autonomous binary bug hunting.
ANSSI's archive of France Cybersecurity Challenge problems, replayable year-round.
Learn modern crypto by breaking it. RSA, ECC, lattices, the works.
Learn ROP through eight progressive pwn challenges. ret2win to ret2csu.
A hacking-challenge platform; this is the leaderboard.
Reverse engineering for noobs: x86, stack frames, and PE files from scratch.
A FLARE-On writeup reversing an shc-compiled shell script.
Google's interactive map of AI risks and controls across the ML lifecycle.
How to actually read client-side JavaScript on a pentest.
The application-security nonprofit. Top Ten, ASVS, cheat sheets, Juice Shop.
Linux Foundation's open-source security effort. Sigstore, SLSA, GUAC.