CHW Cybersecurity Blog and Portfolio
Welcome to CHW World
█
A party engineer named CHW (ID: chw41) specializing in
Web Security, Penetration Testing, and
Red Teaming.
Currently an active member of the CTF teams 竹狐 (TakeKitsune) and i'm downQQ , and a second-cohort Master’s graduate of is1ab (Information Security Laboratory).
Holds OSEP,OSWE, OSWA, OSCP+ certifications.





Work Experience
[OSEP, PEN-300] Instructional notes - Part 3
OSWE PEN-300 筆記 Part 3,整理 Process Injection、DLL Injection、Reflective DLL Injection、Process Hollowing、Antivirus Evasion、VBA Macro、PowerShell 與 Windows API 規避技術等等。
[OSEP, PEN-300] Instructional notes - Part 2
OSWE PEN-300 筆記 Part 2,涵蓋 JScript Phishing、DotNetToJScript、C# Shellcode Runner、SharpShooter、PowerShell Reflection、Win32 API 與 Reflective C# Client-Side Attacks 等等。
[OSEP, PEN-300] Instructional notes - Part 1
OSWE PEN-300 筆記 Part 1,涵蓋 Compiled/Interpreted Language 與 .NET 基礎、Win32 API、Office VBA Macro、PowerShell Shellcode Runner、記憶體內執行與 Calendar Phishing 等等。
[OSWE, WEB-300] Instructional notes
OSWE / WEB-300 instructional notes covering source code review, exploit chain analysis, authentication bypass, deserialization, SSTI, XXE, XSS, CSRF, SSRF, prototype pollution, WAF bypass, and real-world web vulnerability research patterns.
[OSWE, WEB-300] Instructional notes - Part 6
OSWE WEB-300 筆記 Part 6,涵蓋 Dangerous Functions、Bypass Security Filter to Trigger Eval、Dolibarr Eval Filter Bypass RCE、PostgreSQL injection、Bypass WAF、oraza WAF、RudderStack SQLi and Coraza WAF Bypass 等等。