dmk.sh /research
Operator-grade research · est. 2008

Field notes from the offensive side of the line.

Advisories, technical writeups, and methodology essays from the engagements I run. Published carefully: coordinated disclosure, NDA-aware, redacted where it has to be.

Browse posts Advisories
Featured
Research

A kiosk is not a boundary: threat-modeling Cage, Wayland, and Chromium

Part one of a practical series on building a real-world Linux kiosk environment with Debian Trixie, Wayland, Cage, Chromium, TypeScript, CSS, HTML, and a Python backend.
Apr 28, 2026 · 13 min read · LinuxWaylandKiosk
Read advisory
Recent
2026-04-27

The PHP concat operator interruption — a bug I sat on for thirteen years

A first-person account of an unreported bypass of CVE-2010-2191 I found around 2010, never disclosed, and which lived on in shipped PHP until 8.3.0 in November 2023. What I did, what I didn't, and what the project did and didn't.

12 min
2026-03-08

Defeating PHP's internal boundaries — a hardening guide for PHP 8.5

Why every PHP-internal security control collapses in front of FFI or a single memory-corruption primitive — including a practical answer to whether FFI escapes Docker — and what your hardening posture actually needs to look like in 2026.

37 min
2026-01-22

Two audiences, one report: the structure I use for every engagement

The board wants to know whether you're a bigger or smaller problem than the last firm. The engineers want to know which line of code to change. A report that addresses only one of them is not finished.

8 min
Working with me

Engagements run under signed PtA, OPSEC-aware, with reports tailored to two audiences.

Send a brief