I build software and then try to break it. At Pagesync that's the job: we write the code, then attack it before anyone else does. Most days I'm reading source for the one line that lets a stranger in.
Write-ups of what I find, how it got fixed, and the tools I build along the way end up here.
writingall 4 →
disclosuressecurity.txt
- Invoices readable across tenants in a billing API
- Stored XSS through SVG uploads in a self-hosted wiki
- Pre-auth in a plugin
building
elsewhere
- emailkartik@pagesync.in
- github@kr40
- x@kr40_in
- linkedinin/kr40