Blog
Thoughts on development, design, and everything in between.
A Paid API Key Sat In The Page, And It Worked
A law firm site with a review widget that rendered a billable geocoding key into the HTML. The finding is narrow, trivially automatable, and the most profitable line item in the report.
Your Online Shop Exposes A Public API You Did Not Write
A lifestyle and commerce site on a current content platform with a store attached. Seventeen findings, and the store interface was the one nobody audited because it looked like a feature.
A Nonce In The Page Is Not A Secret, And The Plugin Knew It
A business innovation network ran a patched content platform with fourteen findings. The interesting one was a feature left switched on that published its own request tokens in the page source.
Modern Front End, Ancient Back Office: Auditing A Hybrid Estate
A petition platform ran a modern framework on the main domain and a legacy content system behind a raw server with no firewall. The modern side was excellent. The legacy side defined the risk.
What A Ransomware Incident Teaches About The Week Before It Started
A public-sector network was exfiltrated for roughly a week before anyone noticed. This write-up is about the controls that would have shortened that dwell time, not about the attacker.
The API Documentation Was Public, And It Was The Best Map You Can Ask For
An application built with an automated framework served interactive documentation and a machine-readable schema at a well-known path. Both were enabled by default and neither was behind a login.
If TLS Enforcement Is Optional, Version Downgrades Become Boring
A university content platform served mixed protocol versions on some hosts. No cipher was weak, no certificate was expired, and the transport layer still failed the assessment.
A Patched Estate With Six Findings And No Exploits: Reporting Discipline
A restaurant site behind a web application firewall. Every plugin was current, every known exploit failed, and the report still had six findings worth acting on.
One Finding, Maximum Impact: A Permissive Cross-Origin Policy
A civic content platform on a modern stack produced a single finding of the highest severity. It needed no version check and no exploit; the browser already did the work.
A Platform For Internal Communication, Exposed To The Internet
A public-facing cooperation and counselling platform ran a content system with three low-severity findings. The lesson was in what a low-severity result does not tell you.
Error Tracking Telemetry Describes Your Architecture To Anyone With A Browser
A platform provider running a Java backend behind two reverse proxies with a modern front end. The interesting finding was not a vulnerability but an inventory: error tracking revealed the internal structure.
The Legacy Instance Beside The Modern One Is The Real Estate
One organisation ran two generations of a content platform simultaneously. The modern one was current; the legacy one defined the risk, including a client library past end of life.
Static Site, Serverless Functions, Twelve Findings
A site builder platform with a content delivery network in front and functions behind it. The static layer was clean; the function layer and the mail configuration were not.
A Plugin Can Be Current And Still Hand Out Records To Anyone
A fully patched content management system carried a plugin with current releases and twelve findings. The pattern was authorisation: routes that answered before the permission callback ran.
Error Pages Are An Unintentional API Documentation Endpoint
Across a mixed estate the same three leaks appeared again and again: stack traces, framework banners and absolute filesystem paths. Each one maps the internals for free.
The Booking Plugin Is The Product, And The Product Is An Admin Surface
A training provider with a booking plugin exposed to the internet exposed its entire administrative surface with it: exports, attendee records, file uploads and an unauthenticated cron.
A Row Level Security Policy Is A Boundary You Have To Test From The Client Side
A platform-generated application stored every tenant table behind row level security. The policy was correct on paper and bypassable in practice, because the client held a key the policy trusted too much.
Twenty Findings, One Platform: How Volume Changes The Remediation Order
An industrial supplier with a large content surface produced twenty findings across seven categories. The value was in the ordering, not the count.
A Single Page Application Hands You Its Own Route Map
A modern framework application with almost no server-side exposure still revealed its administrative surface, because the route table is compiled into the client bundle.
Eight Attack Vectors, Zero Findings: What A Hardened Single Page Application Looks Like
A negative assessment is a result. This one documents why eight standard vectors failed against a statically served application behind an edge platform.
WordPress User Enumeration Is Not The Finding, It Is The Multiplier
A tax advisory firm exposed every account slug through its public REST API, shipped no security headers at all, and left the login form without rate limiting.
A Legacy Municipal CMS With Perfect Transport Security And No Clickjacking Protection
HSTS was immaculate on a German municipal court portal. One missing header still allowed framing, and the CSP permitted script injection outright.