aurora@hack:~$▌
~/main

~ / cases / arbitrary-file-read

◉ Arbitrary File Read

LFI, path traversal, SSRF chains — reading files and secrets the app never meant to expose.

[docker lab] file-boundary

Test path traversal and learn how filesystem boundaries fail. Run it locally to practice the proof of concept in an isolated environment.

docker compose -f labs/arbitrary-file-read up --build

aurora@hack:~$ ls ./cases/arbitrary-file-read

▲ High8 min read

Trusted Chat to ZIP Upload with Symbolic Links

A trusted chat workflow let an AI scanner download and extract a ZIP containing symbolic links, turning a legitimate-looking coverage report into an arbitrary file read.

#zip#symbolic-links#path-traversal#ai-agent
▲ Critical10 min read

Trusted Chat to Pickle Deserialization via bashExecutor

A chat agent blocked direct .pkl uploads but accepted a ZIP containing a legitimate CSV and a hidden pickle payload, which was later loaded through an exposed execution tool.

#pickle#deserialization#ai-agent#tool-abuse#rce

other classes: rce · prompt-injection-role-confusion · sqli · system-prompt-exfiltration

aurora-hack © 2026 — field notes from a red teamer

responsible disclosure only · no client data, no credentials, ever