Welcome to infophreak

Don't miss our latest intel reports, blogs, and research. Cyber-security intel, research, and community — for phreaks, by phreaks.

Become a Phreak!

Latest Intel

View all →
Exploiting the Ultimate Essay Grader: A Prompt Injection Deep Dive
Offensive Security

Exploiting the Ultimate Essay Grader: A Prompt Injection Deep Dive

A hands-on look at a direct prompt injection vulnerability in an AI essay grader — how a hidden instruction block forced a perfect score, mapped against Pangea's prompt injection taxonomy.

·L0WK3Y
8kSec FactsDroid Walkthrough
Offensive Security

8kSec FactsDroid Walkthrough

Intercepting and modifying network traffic in a Flutter Android app — bypassing root detection and TLS, setting up DNAT for a proper MITM, and a detour into Flutter's HTTP network policy.

·L0WK3Y
Bugforge.io Gift Lab Walkthrough
Web Security

Bugforge.io Gift Lab Walkthrough

A gift-list app's "share link" turns out to be raw Base64 of a sequential list ID — enumerating tokens to access other users' private gift lists.

·L0WK3Y
Bugforge.io CopyPasta Walkthrough
Web Security

Bugforge.io CopyPasta Walkthrough

Chaining an IDOR on the profile endpoint with a broken authorization check on password changes to take over an admin account and grab the flag.

·L0WK3Y
InjuredAndroid Walkthrough: All 13 Flags
Offensive Security

InjuredAndroid Walkthrough: All 13 Flags

A full flag-by-flag walkthrough of the InjuredAndroid CTF app — string comparisons, DES/XOR decryption, exported broadcasts, Firebase misconfigurations, Unicode collisions, intent redirection, and a native RCE binary.

·L0WK3Y
PentesterLab Android Walkthrough: Labs 01–08
Offensive Security

PentesterLab Android Walkthrough: Labs 01–08

Working through PentesterLab's Android series — plaintext strings, SQLite assets, XOR ciphers, AES-CBC, PIN-derived keys, and brute-forcing a key that depends on a server-fetched secret.

·L0WK3Y
KGB Messenger Walkthrough
Offensive Security

KGB Messenger Walkthrough

Reverse engineering an open-source Android CTF practice app across three challenges — fake integrity checks, an MD5-gated login with a XOR-derived flag, and custom cipher messages sent to an in-app chatbot.

·L0WK3Y
IP Halloween 2025 - Spirit Halloween! Walkthrough
Capture The Flag

IP Halloween 2025 - Spirit Halloween! Walkthrough

Walkthrough for infophreak's own Halloween 2025 CTF — directory discovery to an APK, decompiling a native library with JADX, and pulling the flag from an encoded string inside it.

·L0WK3Y
Halloween 2025 CTF Announcement 🎃
Capture The Flag

Halloween 2025 CTF Announcement 🎃

infophreak is hosting their 2025 Halloween CTF from October 1st to October 31st. Compete to win prizes and glory!

·Team
Your next cloud with Nextcloud + Backblaze
Cloud

Your next cloud with Nextcloud + Backblaze

In this tutorial, I will be going over how to set up your very own Nextcloud server using Docker Compose on a public cloud provider like DigitalOcean.

·hikiko
TryHackMe Room Writeup: Sakura
Capture The Flag

TryHackMe Room Writeup: Sakura

This writeup covers the TryHackMe "Sakura" room, featuring an OSINT investigation into a fictitious hacker who attacked the OSINT Dojo. This room is designed to test a diverse range of OSINT techniques, including those related to image, social media, and geolocation intelligence.

·SirPicklJohn
OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company
Intelligence

OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company

This article covers a post-incident OSINT investigation that linked a recent business email compromise back to an Australian carpet company, due to a DNS registration mishap by the attacker. Persistence and pivoting are key for investigators!

·SirPicklJohn