Security
Authorised work only. A written mandate from the owner, or the public policy of a bug bounty program, comes before any test.
Targets are not named on this page. Details are available under an engagement.
- Vulnerability research on a widely distributed game extension. An administrator only action was accepted by the server without any privilege check. Proof of concept written, maintainer notified.
- Penetration test on a controlled preproduction environment, with written authorisation, a scope agreed in advance and third party hosting excluded. Findings ranked by severity.
- Security audit of a client WordPress site : headers, exposed files, attack surface, fixes delivered and verified.
- Review of access rules on an application database, focused on tenant isolation.
- Audit of my own infrastructure, around thirty services, with a phased remediation plan.
A tool enforces an authorisation, it never creates one.