Security
Security
Application security grounded in years of building and maintaining production software.
My security work focuses on how real applications fail: authorization logic, input handling, integrations and the gaps that appear between components. Having built and maintained commercial software, I try to deliver findings and recommendations that development teams can act on.
Areas of specialization
- Web application penetration testing
- Source-code security auditing
- Vulnerability research and assessment
- Application security reviews
- Secure development practices
- Security tooling
Certifications
OSWE · Offensive Security Web Expert
Verify credential (opens in a new tab)Public vulnerability disclosures
Broken object-level authorization across organization and project resources
Publicly disclosed authorization issue in the Tolgee platform, credited to pr0h0 as reporter in the GitHub advisory. See the advisory for affected versions and remediation.
Slack bot-event signature verification bypass
Publicly disclosed issue in the Tolgee platform's Slack integration, credited to pr0h0 as reporter in the GitHub advisory. See the advisory for affected versions and remediation.
Independent research
In addition to the public advisories listed here, I take part in independent, private security research. Details of private reports are not disclosed.
Security tools & research projects
CodeGuardian
A local security auditing tool combining static analysis, existing security scanners, AI-assisted source review, vulnerability triage, and structured reporting.
- TypeScript
- Node.js
- Docker
- SQLite
- Semgrep
- Trivy
XSS-RC
A research framework for turning a confirmed cross-site scripting finding into clear, convincing proof-of-concept evidence during authorized testing.
- Node.js
- Express
- Socket.io
- Tailwind CSS
- Security research
- Authorized testing
- Reporting
XSS Go Scanner
A small Go command-line tool that uses a real browser to check whether web applications safely handle untrusted input, for authorized testing.
- Go
- Browser automation
- Playwright
- CLI
- Browser automation
- Authorized testing
ExposeGuard
An infrastructure exposure validation platform: it checks whether each service is reachable from where it should be — and only from there.
- TypeScript
- Bun
- PostgreSQL
- Python
- Docker
- Exposure management
- Network policy
- Defensive security
Boundary (AI Bug Bounty)
A self-hosted platform for running authorized web security assessments with AI agents kept inside strict, auditable guardrails.
- TypeScript
- PostgreSQL
- Docker
- AI agents
- Governance
- Audit trail
- Authorized testing
Red Team Attack
A self-contained, single-user training range for practising web security skills against a deliberately vulnerable practice app that ships with it.
- TypeScript
- Docker
- Security education
- Training range
- Self-contained
Bug Bounty Codex Plugin
A local assistant plugin that brings structure and discipline to authorized, scoped security research — from scope review to a well-written report.
- Python
- Codex plugin
- Methodology
- Authorized testing
- Reporting
Blue Team Defence
A hands-on secure-coding course for working developers: fix real vulnerabilities in a realistic codebase and get feedback on exactly why a patch falls short.
- TypeScript
- Docker
- React
- gVisor
- Secure coding
- Developer education
- Code review