Skip to content
../home

Security Work

Real-world penetration testing engagements, vulnerability research, and competitive CTF participation. Each finding is responsibly disclosed with actionable remediation guidance.

2024 · Case Study

COEC Platform Security Audit

<target> Node.js / SQLAlchemy / PostgreSQL — Production REST API </target>

// problem

The COEC platform, a production financial technology application, had not undergone a formal security review. As part of an internal audit engagement, I was tasked with identifying vulnerabilities that could compromise user data or system integrity.

// approach

I performed a white-box penetration test combining automated scanning (Burp Suite, SQLMap) with manual testing for OWASP Top 10 vulnerabilities, logic flaws, and authentication/authorization bypasses. The audit focused on the public-facing API surface and authenticated endpoints.

// findings

Unauthenticated PII Exposure via /api/staff

The /api/staff endpoint exposed full staff profiles including national IDs, phone numbers, and salary data without authentication.

CVSS 9.1Critical

JWT Privilege Escalation

JWT implementation flaws: permissions embedded directly in the token payload with no expiry claims, enabling privilege escalation and token replay attacks.

CVSS 8.2High

SQL Injection in User Search Endpoint

User search parameters were concatenated directly into raw SQL queries without parameterized input, allowing database extraction.

CVSS 7.5High

Insecure Direct Object Reference (IDOR)

Transaction records were accessible by incrementing numeric IDs in API endpoints without ownership verification.

CVSS 6.5Medium

Missing Rate Limiting on Auth Endpoints

Login and password reset endpoints lacked rate limiting, enabling brute-force credential attacks.

CVSS 5.3Medium

// impact

All findings were documented in a formal security report with CVSS 3.1 ratings, proof-of-concept payloads, and prioritized remediation steps. The client patched all critical and high-severity findings within two weeks of report delivery.

CTF Platforms