aurora@hack:~$ tree ./cases --by-class
Case Studies
Every case is sanitized before publishing: no client identifiers, real credentials or engagement data.
◉Arbitrary File Read2 cases →
LFI, path traversal, SSRF chains — reading files and secrets the app never meant to expose.
▣Remote Code Execution2 cases →
Deserialization, template injection, unsafe pipelines — getting a shell where there shouldn't be one.
◌Prompt Injection — Role Confusion1 case →
Client-controlled context and message roles that blur the boundary between user content, assistant output and system instructions.
⌗SQL Injection1 case →
Classic and second-order injection — the bug class that never dies, even in modern stacks.
⌁System Prompt Exfiltration1 case →
Testing whether hidden instructions, policies and system context can be extracted from AI-powered applications.