Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Stephen Rees-Carter :laravel:

@valorin@phpc.social
mastodon 4.7.3
  • Open on phpc.social

Friendly Hacker, Speaker, and PHP & Laravel Security Specialist.🕵️
I hack stuff on stage for fun. 😈
I used to be found at: @valorin@infosec.exchange
#searchable

1289 Followers
315 Following
34 Posts
Joined April 25, 2022
Social Links:
https://pinkary.com/@valorin
Newsletter:
https://securinglaravel.com
Course:
https://practicallaravelsecurity.com
Security Audits:
https://valorinsecurity.com
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 3mo ago
Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting. https://securinglaravel.com/security-tip-have-you-heard-of-slopsquatting/ #Laravel
securinglaravel.com
12
1
10
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 36mo ago

One of my favourite (and oh so simple) hacker tricks is to abuse JSON support in APIs and pass TRUE instead of the actual API key. If the code does loose comparison, you don't need the key! 😎 😈 🍿
https://securinglaravel.com/p/security-tip-type-juggling #PHP #Laravel

securinglaravel.com
909
21
572
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2mo ago
Replying to
@thomas@phpc.social I'm hoping to get to more of them next year, I've had to pull back a bit this year.
1
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 8mo ago

It's been 4 months, a lot has happened, but I'm finally back to writing securinglaravel.com!

New Security Tip coming out in a few hours...

9
5
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago

As Laravel's friendly hacker, I feel it is my duty to inform everyone that Laravel v11 is no longer supported! 😱

❌ Bug fixes (they stopped 6 months ago)
❌ Security fixes (they stop today!)

Have you upgraded yet?

https://laravel.com/docs/releases#support-policy #Laravel

laravel.com
6
0
5
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 3mo ago
Working on a fun In Depth article for Securing Laravel at the moment. 😈 The tagline is: What do you get when you combine an API, SameSite=None, and a Session cookie? Any guesses?
1
4
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 5mo ago

Livewire's Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈

https://securinglaravel.com/in-depth-dont-trust-public-livewire-properties/ #Laravel

securinglaravel.com
3
0
3
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago
PSA for Statamic folks - update your sites ASAP! ⚠️ A CRITICAL vuln was discovered that allows full account takeover via password resets! 😱 All the details: https://cvereports.com/reports/CVE-2026-27593 #Laravel
cvereports.com
3
0
9
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 12mo ago

If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands? 🤔

https://securinglaravel.com/security-tip-how-should-apis-respond-to-http/ #Laravel

securinglaravel.com
7
2
5
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 6mo ago

Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data?

https://securinglaravel.com/security-tip-stop-putting-actions-on-get-requests/ #Laravel

securinglaravel.com
2
0
2
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago

You can't trust an email address you haven't verified, so why are you storing them in your database?

https://securinglaravel.com/in-depth-email-verification-isnt-as-simple-as-you-think/ #Laravel

securinglaravel.com
2
0
3
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 5mo ago

I love Signed URLs, but there is one very subtle trap you can accidentally fall into...

https://securinglaravel.com/security-tip-the-signed-url-trap/ #Laravel

securinglaravel.com
1
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 12mo ago

Do you reset your 2FA secret keys when a user toggles TOTP off/on?

It's not just passwords you need to worry about when it comes to authentication and stolen credentials: if an attacker can steal a 2FA secret key, they'll always have a valid TOTP! 😱

https://securinglaravel.com/security-tip-dont-forget-to-regenerate-2fa-secret-keys/ #Laravel

securinglaravel.com
3
0
1
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago

Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access.

https://securinglaravel.com/security-tip-your-jwt-might-be-a-forever-key/ #Laravel

securinglaravel.com
1
0
4
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 10mo ago

Exhausted after #LaraconAU last week, but excited by how it all went!

I was so proud of everyone in my workshop on Wednesday - everyone had a go, and the excitement in the room as they hacked through challenges made it all worth it.

And my talk on Friday was the most absurd and crazy thing I've done on stage (which is saying something), and I've had some great feedback that's already made it worth it. No idea what I'll do next year...

phpc.social
2
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 12mo ago

Laravel Security Tip: Do You Have a Permissions Policy?

What browser features do you have enabled on your site, and what can an XSS attack do if you don't disable them?

https://securinglaravel.com/security-tip-do-you-have-a-permissions-policy/
#Laravel

securinglaravel.com
2
0
1
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 11mo ago

Haven't bought tickets to my Pre-Laracon AU Security Workshop yet?! 😲

I'll be locking in numbers early next week, so get your ticket TODAY or reach out to me directly. ⌛

This is your final warning... ⏰
https://events.humanitix.com/lets-hack-pre-laracon-security-workshop

#Laravel #LaraconAU

events.humanitix.com
1
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 12mo ago

Cookies come in many shapes and sizes, and with multiple attributes just to confuse you... Have you ever wondered what the humble HttpOnly attribute actually does?

https://securinglaravel.com/security-tip-what-is-an-httponly-cookie/ #Laravel

securinglaravel.com
1
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2w ago
Replying to

@yojimbo@masto.hackers.town

From whom are they being protected?

Protected from someone finding their way into my system and accessing my client's details and vulns.

Who is the target audience for a report?

Whoever my client gives access - usually we set up a channel with the dev team, and I report findings directly to them. I don't think I've had a client gatekeep my work from their team before.

0
1
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago
Replying to
@bobmagicii@phpc.social CLI is definitely overlooked too. Limited security risks given they'd have access to the code though. 🤔
0
1
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago

Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error.

https://securinglaravel.com/security-tip-validate-config-at-boot/ #Laravel

securinglaravel.com
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 3mo ago
Recently finished an audit for one of my oldest clients, this was #5! 🕵️ By far the most rewarding part of my job is working with the same clients each year, seeing their apps grow, and their commitment to security strengthen. It's not just a compliance checkbox, it's part of their culture. I've got some capacity coming up, so if you'd like security to be part of your culture too, let's make that happen! Reach out or head over to https://valorinsecurity.com
valorinsecurity.com
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2w ago
How does everyone feel about pentest findings/reports available online (behind auth), as opposed to emailed or sent via Slack/Teams? I've always been wary of putting them online, even behind auth, but I can see some benefits - especially with agents doing the remediation work.
0
2
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 1w ago
Replying to
This article has gone in a direction I didn't expect - a PR into the framework itself! Should be a fun read by the time I'm finished, and will probably end up being a 2-parter.
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 7mo ago

routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one?

https://securinglaravel.com/security-tip-consider-all-routes-not-just-web/

securinglaravel.com
0
1
1
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2mo ago
Um... that's not how risks work... 🤦 This is the rubbish being peddled by big companies selling "Cyber Insurance". 😡
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 3mo ago
Replying to
How would that work? What are you thinking? 🤐
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2w ago
Replying to

@yojimbo@masto.hackers.town Yeah, the PDF reports will never go away, so much of the compliance ecosystem relies on them and they make a good completion-artifact.

I feel like this could be a client preference, rather than a supplier decision, which raises the engagement complexity of course.

This is a good point. It wouldn't be overly hard to do a split system, online for the clients who want it. 🤔

I recently provided .md finding files to a client, who loved them for importing & processing.

0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 8mo ago

I know I say this all the time (especially on stage!), but apparently not everyone heard me, so here we go again...

https://securinglaravel.com/security-tip-update-your-packages-yes-this-again

securinglaravel.com
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2mo ago
What do you get when you combine an API, SameSite=None, and a Session cookie? https://securinglaravel.com/in-depth-three-reasonable-decisions-one-critical-vulnerability/ #Laravel
securinglaravel.com
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2mo ago
Replying to
@thomas@phpc.social No 😭
0
2
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 2mo ago
Replying to
@willpower232@phpc.social Yep. 🤣
0
0
0
0
Open post
Stephen Rees-Carter :laravel: @valorin@phpc.social
· 12mo ago

"Let's Hack!", my Pre-Laracon Security Workshop is just FIVE weeks away! 🎉
(So is @LaraconAU... but let's be honest, priorities.)

Only 11 tickets left, & I need to confirm numbers with the venue, so if you've been thinking about it, now's the time!
👉 https://events.humanitix.com/lets-hack-pre-laracon-security-workshop

events.humanitix.com
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:29:56 UTC