PoC Demonstrations

Authorized-disclosure demonstrations only. These were produced against systems I own or had explicit permission to test, kept as evidence that a reported issue was real and reproducible. The affected vendors were notified and given time to remediate before publication.

Nothing here targets a third party, and nothing here collects or transmits data. The phishing pages say so on the page itself - the point of each was the request captured in Burp Suite, not the destination.

Demonstrations

Open redirect / host-header manipulation

An unvalidated hostname in a redirect parameter let an attacker choose the destination. The landing page is deliberately an obvious dead end so the redirection is unmistakable.

Phishing-awareness demonstration - "CyberCyber"

A crafted link convincing enough to be clicked, written up in Hebrew. Harmless by construction: the page states outright that it is a demo and that nothing was accessed.

Phishing-awareness demonstration - "Ran"

The same technique aimed at a specific recipient, used to make a point about link trust rather than to collect anything.

Burp Suite captures

The raw request/response evidence behind the two reports above, showing exactly what was sent and what came back.