Web application penetration test
Black-box and grey-box testing of a custom customer portal. From mapping and authentication to IDOR, injection and application logic flaws, with a report ranked by risk.
OWASP · Burp Suite · nuclei
Hi, I'm
Cybersecurity, offensive testing, infrastructure and AI.
Most of the time I find the weak spots before an attacker does. I test applications, networks and Active Directory, design the defense and build infrastructure that holds. Lately mostly AI security, especially models running locally inside a company.
I work in cybersecurity, both hands-on and strategically. For years I've run and defended a datacenter, scanned for vulnerabilities, driven their remediation and kept the environment aligned with ISO 27001. As an Information Security Specialist at BESECURED and Security Administrator and Datacenter Manager at KVADOS, I move from the server room all the way to policy. I'm also a member of the KVADOS CSIRT team, so incident response is something I know first-hand.
The offensive side is what I enjoy most. Penetration testing and red teaming, where I look at a system through an attacker's eyes and find the way in before someone else does. I then turn the findings into a clear report and concrete steps that actually reduce the risk.
I'm equally at home in secure infrastructure design and governance. I deal with NIS2, continuity and availability, and more and more with AI security: how companies adopt AI, how to connect locally hosted models with cloud frontier models, and how to keep oversight and compliance over the whole solution.
I fit where security needs to be seen from both sides. Find the weaknesses, then design how to close them.
I like to test by getting my hands on a system from the terminal. Recon, scanning, hitting the weak spot, verifying. Most of the work is done by nmap, nuclei, Burp Suite, Metasploit and a few of my own scripts. I keep Kali close, both under WSL2 and on a dedicated machine.
rt@kali ~ % nmap -sV -sC 10.10.14.8
Starting Nmap 7.95 ( https://nmap.org )
Nmap scan report for 10.10.14.8
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6
80/tcp open http nginx 1.24.0
445/tcp open microsoft-ds Samba 4.19
3389/tcp open ms-wbt-server Microsoft Terminal Services
Service detection performed. 4 hosts up.
rt@kali ~ %
rt@kali ~ % nuclei -u https://target.local -severity medium,high
[high] CVE-2024-3400 exposed management interface
[high] default credentials on /admin
[medium] missing security headers (CSP, HSTS)
[info] nginx version disclosed in Server header
rt@kali ~ % ffuf -u https://target.local/FUZZ -w common.txt
admin [Status: 301]
backup [Status: 403]
api [Status: 200]
rt@kali ~ %
rt@kali ~ % hashcat -m 1000 ntlm.hash rockyou.txt
Session..........: hashcat
Status...........: Cracked
Recovered........: 18/42 (42.86%) Digests
Speed.#1.........: 9183.4 MH/s
rt@kali ~ % john --show ntlm.hash | tail -3
svc_backup:Autumn2024!
helpdesk:Welcome1
rt@kali ~ %
rt@kali ~ % nxc smb 10.10.14.0/24 -u svc_scan -p '***'
SMB 10.10.14.8 445 DC01 [+] corp.local\svc_scan (Pwn3d!)
SMB 10.10.14.21 445 FS01 [+] corp.local\svc_scan
rt@kali ~ % bloodhound-python -d corp.local -c All
INFO: Found 142 users, 38 groups, 12 computers
INFO: Compressing output into corp_bh.zip
INFO: shortest path to Domain Admins: 3 hops
rt@kali ~ %
rt@kali ~ % bat report/findings.md
# Findings — ACME web application
SEV ID TITLE
CRIT F-01 SQL injection in /api/search
HIGH F-02 IDOR on /invoice/:id
HIGH F-03 broken access control on /admin
MED F-04 missing security headers
FIXED F-00 verbose error disclosure
5 findings · ranked by risk · draft v2
rt@kali ~ %
The other half of the work is less visible but just as important. Vulnerability scans, findings mapped to ISO 27001 and NIS2, risk management. And increasingly locally hosted models, their link to the cloud and oversight of where the data flows.
rt@lab ~ % nessuscli scan summary q3-infra
Scan name....: Q3 Internal Infrastructure
Hosts........: 128 scanned, 126 responsive
Critical.....: 3 High: 11 Medium: 42
Top findings.: MS17-010, outdated OpenSSL, weak TLS
rt@lab ~ %
ID FINDING ISO A. NIS2 STATUS
F-01 weak TLS configuration A.8.24 yes open
F-02 no MFA on remote VPN access A.8.5 yes open
F-03 patch SLA exceeded on DC01 A.8.8 yes remediated
F-04 insufficient audit logging A.8.15 yes open
F-05 no formal risk register A.5.9 - remediated
5 of 27 findings · mapped to ISO 27001 Annex A + NIS2
rt@lab ~ %
1 services:
2 ollama:
3 image: ollama/ollama:latest
4 volumes: [./models:/root/.ollama]
5 deploy: { gpus: all }
6 open-webui:
7 image: ghcr.io/open-webui/open-webui:main
8 ports: [3000:8080]
9 mcp-gateway:
10 build: ./mcp/
11 environment: [FRONTIER_API=cloud]
rt@lab ~ % ollama list
NAME SIZE MODIFIED
llama3.1:70b 40 GB 2 days ago
qwen2.5-coder:32b 20 GB 5 days ago
nomic-embed-text 274 MB 1 week ago
rt@lab ~ % curl localhost:11434/api/tags | jq length
3
rt@lab ~ %
Black-box and grey-box testing of a custom customer portal. From mapping and authentication to IDOR, injection and application logic flaws, with a report ranked by risk.
OWASP · Burp Suite · nuclei
A view from inside the LAN. Recon, traffic sniffing, Active Directory attacks and lateral movement up to domain admin.
nmap · BloodHound · Metasploit
A targeted-attacker scenario. Phishing as the entry point, quiet movement through the environment and a check of what detection and the team actually catch.
OSINT · C2 · MITRE ATT&CK
Gap analysis, risk management, policies and a statement of applicability. So the audit passes and security makes sense outside the IT department too.
ISO 27001 · NIS2 · risk management
Setting up regular scanning, triage and remediation. Turning a one-off check into a continuous process with measurable progress.
Tenable Nessus · patch management
Design and operation of models running inside the company, their connection to cloud models and oversight of data, access and compliance.
Ollama · Open WebUI · MCP · Docker