Security

Authorised work only. A written mandate from the owner, or the public policy of a bug bounty program, comes before any test.

Targets are not named on this page. Details are available under an engagement.

  • Vulnerability research on a widely distributed game extension. An administrator only action was accepted by the server without any privilege check. Proof of concept written, maintainer notified.
  • Penetration test on a controlled preproduction environment, with written authorisation, a scope agreed in advance and third party hosting excluded. Findings ranked by severity.
  • Security audit of a client WordPress site : headers, exposed files, attack surface, fixes delivered and verified.
  • Review of access rules on an application database, focused on tenant isolation.
  • Audit of my own infrastructure, around thirty services, with a phased remediation plan.

A tool enforces an authorisation, it never creates one.

security.txt