Security
Security
I build software secure by default, and I break it to understand how. That means application security from the builder’s side, hands-on lab work, and a discipline that matters more than any tool: test only with permission, stay inside scope, and write a report the people who have to fix things can actually act on.
Labs
All labs →Writing
- 3 October 202612 minA pentest lab on Apple Silicon (and what a frontend dev did with root)Most lab guides assume an Intel machine and VirtualBox, which falls apart on an M-series Mac. Here is the one insight that fixes it, the seven phases of a pentest walked end to end against a real target, and the part where a frontend developer got hold of root and could not resist writing CSS with it.
- 25 September 20268 minA security checklist my coding agent has to runMost security checklists say what should be true and never get tested. Here is what happened when every item was rewritten as something you run, and packaged as a skill a coding agent loads before it writes the code.
- 14 September 202610 minWhat my WAF actually blocked, and what my app already stops on its ownI ran 26 attack payloads against a production app with ModSecurity on and off. It blocked 12: five my app already rejected, and seven it stopped a step earlier than the app's own defences. The class behind most real breaches never showed up in either column.
- 10 September 20267 minEthical hacking is not a toolset, it is a mindset with a permission slipHacker, ethical hacker and penetration tester are not the same thing, and one of the differences is an invoice versus a criminal record. The mindset, the seven-stage method, and the black, grey and white box styles, laid out plainly.