pr0h0

Security

Security

Application security grounded in years of building and maintaining production software.

My security work focuses on how real applications fail: authorization logic, input handling, integrations and the gaps that appear between components. Having built and maintained commercial software, I try to deliver findings and recommendations that development teams can act on.

Areas of specialization

  • Web application penetration testing
  • Source-code security auditing
  • Vulnerability research and assessment
  • Application security reviews
  • Secure development practices
  • Security tooling

Certifications

Public vulnerability disclosures

GHSA-535f-x3hw-p4p8 High severity

Broken object-level authorization across organization and project resources

Tolgee Platform · 2 Jun 2026

Publicly disclosed authorization issue in the Tolgee platform, credited to pr0h0 as reporter in the GitHub advisory. See the advisory for affected versions and remediation.

Read advisory (opens in a new tab)
GHSA-4mw7-vff5-96jj High severity

Slack bot-event signature verification bypass

Tolgee Platform · 2 Jun 2026

Publicly disclosed issue in the Tolgee platform's Slack integration, credited to pr0h0 as reporter in the GitHub advisory. See the advisory for affected versions and remediation.

Read advisory (opens in a new tab)

Independent research

In addition to the public advisories listed here, I take part in independent, private security research. Details of private reports are not disclosed.

Security tools & research projects

Security Tools

XSS Go Scanner

A small Go command-line tool that uses a real browser to check whether web applications safely handle untrusted input, for authorized testing.

  • Go
  • Browser automation
  • Playwright
  • CLI
  • Browser automation
  • Authorized testing