Research · From delivered engagements
Notes from the keyboard.
Technique, not thought leadership. Everything here comes out of delivered engagements, and every claim in it is one you can test against your own system this afternoon.
Writing
-
Multi-tenancy
One query that forgot the tenant
The platform had tenant scoping in its data layer, applied consistently, on every query but one. That one was in a service written by a different team for a feature nobody considered sensitive. -
API security
Your API returns more than your interface shows
The interface shows a name. The response contains the record. Nothing is broken, nothing alerts, and the data is gone. -
Chaining
Three low findings and an account takeover
A previous report had listed all three of these findings as low severity and the client had deferred all three. Each rating was defensible. Together they were an account takeover, which is the problem with rating findings one at a time. -
Authentication
The password reset token that survives an email change
The class only shows up when you change the account underneath a live token and then try to use it, which is why testing tokens in isolation never finds it. -
Methodology
The eight checks a finding should survive before you report it
Every finding that reaches a client has cleared eight checks first, because a report’s credibility is spent by its first false positive. -
Business Logic
Nothing was malformed and the money still left
Every request we sent to this checkout was valid. The platform accepted all of them, logged all of them, alerted on none of them, and lost money on each one. -
Access Control
The role that was not a role
A read-only account on a B2B platform could export the data its own screens refused to display. We found it in the first hour of authenticated testing, and the reason it survived two previous tests is worth more than the bug. -
API security
Payment API vulnerabilities worth knowing about
Payment APIs fail at logic, not cryptography, and logic failures settle in real money. -
Web security
Web cache poisoning: exploiting an unkeyed input
A single request can poison a cache entry that is then served to every visitor behind it, which is why impact scales with hit rate rather than with effort. -
Web3
Web3 security exposed: hunting vulnerabilities in dApps
Immutable code raises the stakes of every bug: there is no patch Tuesday for a deployed contract. -
Authentication
Next-level strategies for 2FA authentication bypass
Two-factor authentication raises the cost of an attack. It does not remove it, and here is where it gives. -
AI security
From chatroom to cyber threat: securing AI chatbots
A chatbot holds sensitive data, learns from whatever it is fed, and acts on instructions it cannot tell apart from data: three attack surfaces in one component. -
Linux
Mastering Linux privileges: from fundamentals to escalation
Most Linux escalation is not an exploit at all, but a permission someone granted for a good reason and then forgot about.
Testing you can check
The methodology behind this writing is published in full, including the verification gate every finding passes.