<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>pok3 // security notes</title><link>https://pok3.xyz/</link><description>Recent content on pok3 // security notes</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 27 Sep 2026 15:13:38 -0400</lastBuildDate><atom:link href="https://pok3.xyz/index.xml" rel="self" type="application/rss+xml"/><item><title>Parsing YAML is a minefield</title><link>https://pok3.xyz/posts/parsing-yaml-is-a-minefield/</link><pubDate>Sun, 27 Sep 2026 15:13:38 -0400</pubDate><guid>https://pok3.xyz/posts/parsing-yaml-is-a-minefield/</guid><description>&lt;p&gt;Not long ago I was researching the behavior of YAML parsing libraries as part of my master&amp;rsquo;s thesis. Since there is a &#10;&lt;a href="https://yaml.org/spec/1.2.2/" class="ext" target="_blank" rel="noopener noreferrer"&gt;YAML specification&lt;/a&gt;&#10;, I wanted to assess whether the parsing libraries listed on the official &#10;&lt;a href="https://yaml.org/libraries/" class="ext" target="_blank" rel="noopener noreferrer"&gt;yaml.org&lt;/a&gt;&#10; website comply with the current specification. My idea is hugely inspired by Nicolas Seriot&amp;rsquo;s &#10;&lt;a href="https://seriot.ch/security/parsing_json.html" class="ext" target="_blank" rel="noopener noreferrer"&gt;Parsing JSON is a minefield&lt;/a&gt;&#10;^[&#10;&lt;a href="https://seriot.ch/security/parsing_json.html" class="ext" target="_blank" rel="noopener noreferrer"&gt;https://seriot.ch/security/parsing_json.html&lt;/a&gt;&#10;], which I definitely recommend reading.&lt;/p&gt;</description></item><item><title>publications</title><link>https://pok3.xyz/publications/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pok3.xyz/publications/</guid><description/></item><item><title>whoami</title><link>https://pok3.xyz/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://pok3.xyz/about/</guid><description>&lt;p&gt;Hi, I&amp;rsquo;m &lt;strong&gt;pok3&lt;/strong&gt;. I&amp;rsquo;m a penetration tester and CTF player who spends most of his time analyzing applications or devices for vulnerabilities, to make the world and the software we rely upon everyday a tiny bit safer.&lt;/p&gt;&#10;&#10;&lt;h2 id="what-i-do" class="heading"&gt;&#10; &lt;a href="#what-i-do" class="heading-anchor" aria-label="Link to this section"&gt;#&lt;/a&gt;What I do&#10;&lt;/h2&gt;&#10;&lt;p&gt;I mostly work on web applications and embedded devices: finding the bug, understanding &lt;em&gt;why&lt;/em&gt; it exists, and helping vendors fix it. These days I also play around with AI a lot: Understand its capabilities, figure out how we can efficiently use it for offensive security and how we can secure it.&lt;/p&gt;</description></item></channel></rss>