╔════════════════════════════════════════════════════════════════════════════╗
║ //BEGIN TRANSMISSION REF // SSS-0xCODY ║
╠════════════════════════════════════════════════════════════════════════════╣
║ ║
║ OPERATOR ......... Cody Richard ║
║ CALLSIGN ......... ssstrickys ║
║ ROLE ............. Offensive Security Operator · Red Team ║
║ FOCUS ............ Recon · Exploit Tooling · Active Directory ║
║ DAILY DRIVER ..... Kali Linux · terminal-native · Python (uv) + Bash ║
║ POSTURE .......... Authorized engagements only · every action logged ║
║ DISPOSITION ...... Ships bold. Builds in the dark. Releases in the open. ║
║ ║
╚════════════════════════════════════════════════════════════════════════════╝
Offensive-security operator who lives in the terminal — Kali on the daily driver,
nmapand BloodHound on the wire, HackTheBox and CTF rigs for reps, Python (uvtoolchain) and bash for everything in between. I build my own tooling: when the thing I need doesn't exist, I write it.Operating doctrine: if the tooling doesn't exist, write it; if it's risky, gate it; if it acts, log it.
[ RECON ] · [ EXPLOIT TOOLING ] · [ ACTIVE DIRECTORY ] · [ LINUX INTERNALS ] · [ TOOLING DEV ]
Vulnerabilities reported under published disclosure programs, coordinated with maintainers, and tracked to fix. Full write-ups → ssstrickys.com/research
Target: koala73/worldmonitor · Tauri 2 / Rust / TypeScript · real-time global intelligence platform
| Severity | CVSS | Advisory | Class |
|---|---|---|---|
| 🔴 High | 8.8 | GHSA-2x6r-qq54-mmhr | CWE-78 · Windows command injection (Tauri open_url IPC) |
| 🔴 High | 7.5 | GHSA-r649-4cqj-w93h | CWE-306/639 · Unauthenticated cross-tenant read (BOLA) |
| 🟠 Moderate | 5.3 | GHSA-c267-988w-7pq7 | CWE-290/807 · Rate-limit bypass via spoofable IP header |
| 🟠 Moderate | 4.3 | GHSA-hcq5-jm84-2395 | CWE-770 · MCP daily cost-cap bypass |
| ⚪ Low | 2.7 | GHSA-f6gj-3v7v-j75q | CWE-613 · OAuth refresh-token reuse without family revocation |
Also credited in the project's Security Acknowledgments and PR #1103 (cache-key hardening).