st0pw4r blog
Home Tags About
  • When the WAF Blocks Everything: SQL Injection with Only Math

    March 27, 2026
    security sql-injection mssql waf-bypass

    Recently I came across an interesting bug bounty target where I found some nice, classic SQL injection, but none of the WAF bypasses known to me worked. So I asked Claude Code what it could do to exploit it. It turned out to be quite capable of solving this issue....

  • Caught in the Hook... or just API key exfiltration:

    February 27, 2026
    security ai-agents claude-code

    In my previous post, I explained the concept of the folder trust gap in AI agents. And today someone released a new article which describes such vulnerabilities in Claude Code. Nothing new except an interesting attack vector with environment variables. Caught in the Hook: RCE and API Token Exfiltration Through...

  • The Trust Gap: Your AI Agent Is Running Code Before It Asks Permission

    February 26, 2026
    security ai-agents

    What is the threat model of an AI agent that operates in your terminal? One of the first things that happens when you type claude/codex/copilot/gemini in your terminal is that you are asked to trust this folder before any action is taken. This is a security measure to prevent malicious...

© 2026 st0pw4r blog

Twitter RSS