Web application security is about understanding how trust breaks down — authentication assumptions, cache logic flaws, injection points developers never considered an attack surface.
Attack Surface
How I Operate
Tooling
Current Operation
The writeups are the work. Everything else is just context.
48 labs documented across authentication, web cache deception, SQL injection, path traversal, and OS command injection. Access control in progress.
© 2026 Gurpreet Singh — CC BY-NC-ND 4.0. Feel free to reference for learning; don't submit as your own work.