./recon.sh --target self 

Gabriel Hinostroza

Penetration Tester · Web, API, Android, Active Directory

Penetration tester focused on web applications, APIs, Android and Active Directory infrastructure. I report what I find through coordinated disclosure, and publish the analysis once the fix is out.

CRITICAL CVE
CVE-2026-2586
9.1
Eclipse GlassFish · Authenticated RCE · Published
04
CVEs filed
9.1
top CVSS
11
write-ups
01

About me

Full profile →

What I work on and how I disclose it.

I work on web applications, APIs, Android and Active Directory infrastructure. Most of what I find comes from reading code and protocols carefully rather than from running scanners.

Everything I report goes through coordinated disclosure, and I publish the write-up once the fix is out — the finding is only half the work.

Specialisations

Web VAPTAPI SecurityAndroid Active DirectorySource Code Review Out-of-band / SSRFXXE

Tooling

Burp SuitenmapBloodHound MetasploitFridaMobSF ffufIntrospector
02

Published CVEs

All CVEs →

Coordinated disclosure. Click through for the full analysis.

The File Manager does not verify that the session identifier belongs to the authenticated user, which chains into remote code execution.

Broken Access Control → RCECVSS 9.0

The File Manager's path parameter accepts command substitution syntax.

OS Command InjectionCVSS 9.0

The database export exposes any user's password reset codes, allowing the takeover of other accounts.

Account TakeoverCVSS 8.8
03

Tools

All repos →

Built while testing, because I needed them.

Introspector

Python

Out-of-band operations framework. HTTP and DNS callbacks with correlation tokens that tell you which injection point fired, DNS exfiltration decoding, payload hosting and byte-exact responses for what a real HTTP server refuses to send.

FastAPISQLiteAGPL-3.0 GitHub →

GlassFish Research

CVE-2026-2586

The research behind the authenticated RCE in Eclipse GlassFish: how the admin console reaches command execution.

CVSS 9.1 GitHub →

Termix Research

CVE-2026-45746 · 45750

Two findings in Termix — broken access control and command injection — chained into remote code execution.

CVSS 9.0 GitHub →
04

Research & write-ups

All write-ups →

Original research and Hack The Box machines, start to finish.

Tabby

HTB

Tomcat manager to host compromise.

Active Directory, start to finish.

05

Certifications

All →

Offensive security, web and mobile.

eWPTX certificate issued to Gabriel Hinostroza Ayala

eWPTXv3

INE

Web Application Penetration Tester eXtreme.

eJPT certificate issued to Gabriel Hinostroza Ayala

eJPTv2

INE

Junior Penetration Tester.

Certified Mobile Pentester Android certification badge

CMPen-Android

SecOps Group

Certified Mobile Pentester – Android.

06

Get in touch

Decode the key.

Base64 · Decode the payload and use the result as the email subject.

-----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAAB AAAAMwAAAAtzc2gtZWQyNTUxOQAAACBHYWJyaWVsSEExMmNoYWxs ZW5nZS1lbnVtZXJhdGlvbi1iYXNlNjQAAAAEc2VjcmV0AAAA Y2hhbGxlbmdlOiBlbnVtZXJhdGlvbg== AAAAC3NzaC1lZDI1NTE5AAAAIEdINFMtcmVzZWFyY2gtb25seQ== -----END OPENSSH PRIVATE KEY-----