Security Work
Real-world penetration testing engagements, vulnerability research, and competitive CTF participation. Each finding is responsibly disclosed with actionable remediation guidance.
COEC Platform Security Audit
// problem
The COEC platform, a production financial technology application, had not undergone a formal security review. As part of an internal audit engagement, I was tasked with identifying vulnerabilities that could compromise user data or system integrity.
// approach
I performed a white-box penetration test combining automated scanning (Burp Suite, SQLMap) with manual testing for OWASP Top 10 vulnerabilities, logic flaws, and authentication/authorization bypasses. The audit focused on the public-facing API surface and authenticated endpoints.
// findings
Unauthenticated PII Exposure via /api/staff
The /api/staff endpoint exposed full staff profiles including national IDs, phone numbers, and salary data without authentication.
JWT Privilege Escalation
JWT implementation flaws: permissions embedded directly in the token payload with no expiry claims, enabling privilege escalation and token replay attacks.
SQL Injection in User Search Endpoint
User search parameters were concatenated directly into raw SQL queries without parameterized input, allowing database extraction.
Insecure Direct Object Reference (IDOR)
Transaction records were accessible by incrementing numeric IDs in API endpoints without ownership verification.
Missing Rate Limiting on Auth Endpoints
Login and password reset endpoints lacked rate limiting, enabling brute-force credential attacks.
// impact
All findings were documented in a formal security report with CVSS 3.1 ratings, proof-of-concept payloads, and prioritized remediation steps. The client patched all critical and high-severity findings within two weeks of report delivery.