Skip to content

Repository files navigation

Security Writeups

Selected security research and vulnerability writeups by Md. Azmol Haque Rony (@azmolhaque).

📄 Writeups

A measured, reproducible look at prompt-injection resistance in a small local LLM (Llama 3.2 3B, via garak, 256 trials per attack). The same model was hijacked 46.9% of the time by one payload but only 10.2% by another — a 4.6× content-dependent gap whose 95% confidence intervals don't overlap.

The core lesson: injection resistance is a distribution, not a single number — test one payload and you can be off by multiples from your real threat. Includes the safety-training explanation, the defender's takeaways, full reproduction steps on a Raspberry Pi, and honest limitations (including a third probe that stalled and why it was excluded).

🌐 Also available in 9 languages — see the language bar at the top of the writeup (English · Español · Français · Deutsch · العربية · हिन्दी · বাংলা · 简体中文 · 日本語).

A total authentication bypass on a Google-acquisition asset (rip.photomath.net) — default credentials, any password accepted, and an unauthenticated backend API. Triaged P2/S2, Fixed in 9 days, and awarded credit (Honorable Mention), not cash.

The writeup does the harder thing: it explains, at a mechanism level, why "fixed fast" and "not rewarded" were both correct — the root cause was a stale DNS record on un-migrated acquisition infrastructure, not a defect in an operated system. Includes the repeatable detection method, the edge-fronted ≠ operated distinction, a reward-bar counterfactual, and a defender's-eye remediation plan. Full PoC evidence embedded.

Reported via Google Bug Hunters (Issue 509594209). Endpoint remediated before publication.

🌐 Also available in 9 languages — see the language bar at the top of the writeup (English · Español · Français · Deutsch · العربية · हिन्दी · বাংলা · 简体中文 · 日本語).

A short, plain-language version of the same story — written for a general audience. If the full writeup is the engineering deep-dive, this is the five-minute read about why calibrated judgment matters more than a payout.

About

Responsible-disclosure security writeups — web app & infrastructure findings, with honest severity analysis.

Resources

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages