kivirstan

Hey, I'm Riley :3

I'm an 18 year old enby from New Zealand, my Mum says I think too much. In my free time, I'm a gay fox on the internet breaking as much shit as humanly possible. I'm responsible for 17 CVE submissions and I have commendations from PayPal, Google and Tesla. Anyways, enjoy my schizophrenic infodumping and occasional wisdom.

Telegram iconDiscord iconGithub iconYoutube icon
Me irl
Dumb shit I've worked on
apk2firebase logo
apk2firebase
Python
Firebase
Android
Java

An intuitive way to parse Firebase credentials from .apk files and automatically test them.

JWTFinder logo
JWTFinder
JavaScript
JSON Web Token
Chromium

Browser extension that monitors all network requests, searches them for JWT tokens and decodes the data.

TenantHunter logo
TenantHunter
Python
Azure

Resolves domains to Azure tenant IDs and login portals.

PHPGitPwny logo
GitPwny
Go
PHP
Git

Scan Git repositories and profiles for PHP functions that look vulnerable and saves them for further analysis.

LaravelScraper logo
LaravelScraper
Python
Laravel
Shodan
Telegram

Scrapes Laravel error pages via Shodan, downloads and parses the results, then displays all credentials reported in the error page and (optionally) reports them to a Telegram bot.

Dumb shit I wrote
PyInstaller demonstrating compiling a .py into a .exe/.ELF

Investigating PyInstaller Malware In Bulk

Dec 2, 2024
Infostealers, malware and Python. A recipe for disaster impacting skids that don't know better.
Spring Boot logo

Fuzzing 98,000 Random Spring Boot Servers For AWS S3 Keys

Jun 6, 2024
Why leaving heapdump endpoints exposed can lead to disastrous consequences.
IBM ThinkPads on the Libreboot GRUB menu

Librebooting, ThinkPads And Intel ME Hell

Mar 16, 2023
How Intel ME works and why we need to reconsider our perspective on what spyware truly means.
🄯 Copyleft 2025 by Riley Kivimäki. This site and its owner are proudly pro-para!