aurora@hack:~$ whoami
Offensive Cybersecurity
aurora@hack:~$ cat about.md
I am an offensive cybersecurity professional with hands-on experience in penetration testing, vulnerability analysis, threat detection, and security assessment of AI systems.
> knowledge & focus
- Web & API pentesting
- iOS & android pentesting
- AI/ML & MCP security
- Active directory
- Homelab research
Open-source Docker labs: github.com/shagen1212/aurora-hack-labs
aurora@hack:~$ cat mission.txt
Field notes from pentesting in the age of AI agents.
Real engagements, sanitized: how the bug worked, how I found it, the script I wrote, and what it taught me. Heavy on the new attack surface — LLMs and autonomous agents inside client systems.
aurora@hack:~$ ./explore --sections main cases▌
aurora@hack:~$ ls ./attack-surface
◉ arbitrary-file-read/
Arbitrary File Read
LFI, path traversal, SSRF chains — reading files and secrets the app never meant to expose.
[docker lab] file-boundary
Test path traversal and learn how filesystem boundaries fail.
docker compose -f labs/arbitrary-file-read up --build▣ remote-code-execution/
Remote Code Execution
Deserialization, template injection, unsafe pipelines — getting a shell where there shouldn't be one.
[docker lab] unsafe-pipeline
Practice identifying and containing an unsafe document pipeline.
docker compose -f labs/rce up --build◌ prompt-injection-role-confusion/
Prompt Injection — Role Confusion
Client-controlled context and message roles that blur the boundary between user content, assistant output and system instructions.
[docker lab] role-boundary
Test prompt injection caused by manipulated chat-selection roles.
⌗ sql-injection/
SQL Injection
Classic and second-order injection — the bug class that never dies, even in modern stacks.
[docker lab] query-playground
Explore injection safely against an isolated training database.
docker compose -f labs/sqli up --build⌁ system-prompt-exfiltration/
System Prompt Exfiltration
Testing whether hidden instructions, policies and system context can be extracted from AI-powered applications.
[docker lab] prompt-leak
Probe prompt disclosure safely with canaries and defensive checks.