ls -la ./PoC
PoC Demonstrations
Authorized-disclosure demonstrations only. These were produced against systems I own or had explicit permission to test, kept as evidence that a reported issue was real and reproducible. The affected vendors were notified and given time to remediate before publication.
Nothing here targets a third party, and nothing here collects or transmits data. The phishing pages say so on the page itself - the point of each was the request captured in Burp Suite, not the destination.
Demonstrations
Open redirect / host-header manipulation
An unvalidated hostname in a redirect parameter let an attacker choose the destination. The landing page is deliberately an obvious dead end so the redirection is unmistakable.
Phishing-awareness demonstration - "CyberCyber"
A crafted link convincing enough to be clicked, written up in Hebrew. Harmless by construction: the page states outright that it is a demo and that nothing was accessed.
Phishing-awareness demonstration - "Ran"
The same technique aimed at a specific recipient, used to make a point about link trust rather than to collect anything.
Burp Suite captures
The raw request/response evidence behind the two reports above, showing exactly what was sent and what came back.