Command Injection Taxonomy for Code Review

Lab Python ping wrapper: subprocess shell=True vs argv list, dangerous call, the fix, ASAN-irrelevant crash on a C popen helper — no reverse shell.

September 5, 2020 · 7 min · 1293 words · Jose Adalberto Gutierrez Ochoa

SQL Injection Probing Methodology for Analysts

Lab Flask+SQLite app: concatenated vs parameterized queries, SQL logs, WAF noise, ASAN-irrelevant crash on the concat path — no production DB dump.

February 18, 2020 · 6 min · 1215 words · Jose Adalberto Gutierrez Ochoa

JWT Failure Modes Defenders Still See

Lab JWT verifier in Go: decoded header/payload dumps, alg=none rejected, wrong aud rejected, HS256 with a lab secret — no forged production tokens.

July 22, 2019 · 6 min · 1257 words · Jose Adalberto Gutierrez Ochoa

HTTP Request Smuggling: A Defender Mental Model

Lab walkthrough of HTTP/1.1 framing disagreement: raw frames, nginx vs Python http.server parse notes, sanitized logs, hop-boundary hardening.

March 12, 2019 · 7 min · 1350 words · Jose Adalberto Gutierrez Ochoa