kivirstan

Hey, I'm Riley :3

I'm a 19 year old enby from New Zealand, my Mum says I think too much. In my free time, I'm a wolf on the internet breaking as much shit as humanly possible. I'm responsible for 17 CVE submissions and I have commendations from PayPal, Google and Tesla. Anyways, enjoy my schizophrenic infodumping and occasional wisdom.

Telegram iconDiscord iconSignal iconGithub icon
Me irl
Dumb shit I've worked on
apk2firebase logo
apk2firebase
Python
Firebase
Android
Java

An intuitive way to parse Firebase credentials from .apk files and automatically test them.

JWTFinder logo
JWTFinder
JavaScript
JSON Web Token
Chromium

Browser extension that monitors all network requests, searches them for JWT tokens and decodes the data.

TenantHunter logo
TenantHunter
Python
Azure

Resolves domains to Azure tenant IDs and login portals.

PHPGitPwny logo
GitPwny
Go
PHP
Git

Scan Git repositories and profiles for PHP functions that look vulnerable and saves them for further analysis.

LaravelScraper logo
LaravelScraper
Python
Laravel
Shodan
Telegram

Scrapes Laravel error pages via Shodan, downloads and parses the results, then displays all credentials reported in the error page and (optionally) reports them to a Telegram bot.

Dumb shit I wrote
A picture of the glorious Q10 Android box surrounded by coding graphics

Decrappifying A Cheap Android TV Box

Oct 6, 2025
Chinese malware? In THIS economy? On MY TV?
PyInstaller demonstrating compiling a .py into a .exe/.ELF

Investigating PyInstaller Malware In Bulk

Dec 2, 2024
Infostealers, malware and Python. A recipe for disaster impacting skids that don't know better.
Spring Boot logo

Fuzzing 98,000 Random Spring Boot Servers For AWS S3 Keys

Jun 6, 2024
Why leaving heapdump endpoints exposed can lead to disastrous consequences.
🄯 Copyleft 2025 by Riley Kivimäki. This website and its owner are proudly pro-queer and pro-para!