About

Hi, I’m Arthur 👋

I’m Arthur, better known online as Vozec. I work as a cybersecurity researcher focused on offensive security, bug bounty, and pentesting.

Most of my day-to-day is finding bugs that matter: chaining unintended behaviors in real-world software, hunting for novel vulnerabilities in CMS/web stacks, and writing reliable exploits.

What I do

  • Bug bounty. Continuous research on public and private programs, with a focus on web, authentication, and deserialization bugs.
  • Offensive research. Auditing applications source-to-sink, publishing CVEs and writeups when responsibly disclosed. Recent work: my research on the Jalios CMS and a SPIP pre-auth RCE .
  • Pentesting. External, internal, and web-application engagements; reporting in a way that’s actionable for the dev teams on the other side.

CTF & community

I play CTFs whenever I can: FCSC, PwnMe, leHACK, insomni’hack, and many one-shots. The Writeups section covers most of what I’ve solved and felt worth writing up. The articles in RSA , AES , and Crypto Other are deeper dives into the cryptography I love: RSA attacks, AES cryptanalysis, lattice basics, ECC.

Where to find me

Open-source tools

A non-exhaustive list of things I’ve built and shared.

🔒 Cryptography

🔨 Reverse engineering

🚩 CTF tooling & misc