<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Tooling on Jonah Owen</title>
		<link>https://newo-j.github.io/tags/tooling/</link>
		<description>Recent content in Tooling on Jonah Owen</description>
		<generator>Hugo</generator>
		<language>en-gb</language>
		
		
		
		
			<lastBuildDate>Tue, 12 May 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://newo-j.github.io/tags/tooling/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Building a Concurrent Diffing Engine for IDOR/BOLA Triage</title>
				<link>https://newo-j.github.io/projects/diffing-engine/</link>
				<pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate>
				<guid>https://newo-j.github.io/projects/diffing-engine/</guid>
				<description>&lt;figure class=&#34;fig&#34; style=&#34;--fw:120%&#34;&gt;&#xA;  &lt;img src=&#34;https://newo-j.github.io/images/diffy.png&#34; alt=&#34;AirGap-Diffy&#34; width=&#34;1920&#34; height=&#34;1080&#34;&#xA;       loading=&#34;eager&#34; decoding=&#34;async&#34;&gt;&#xA;&lt;/figure&gt;&#xA;&#xA;&lt;p&gt;During my time at Synack Red Team, the scope of real-world penetration tests initially felt overwhelming to me.&#xA;Us researchers would often be assigned massive scopes of data to audit that is unlike anything seen in a lab environment such as HackTheBox.&lt;/p&gt;&#xA;&lt;p&gt;Fellow SRT&amp;rsquo;ers suggested I pick a vulnerability class, and get good at it - I found myself doing well with Access Control / IDOR vulnerabilites and ended up landing my first critical (CVSS 9.1) bug bounty that way.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
