Stephen Rees-Carter

@valorin.bsky.social

Friendly Hacker, Speaker, and PHP & Laravel Security Specialist.🕵️ I write securinglaravel.com and hack stuff on stage for fun. 😈 I'm found elsewhere too: https://pinkary.com/@valorin 🪄

One of the most satisfying (and most frustrating!) parts of pentesting is spending an hour setting up the perfect PoC, composing shock-value screenshots, and writing a succinct report - only for them to spend 30 seconds making a trivial code change that fixes the issue. 😈😱

Received some great feedback from a client recently, and it really highlights why I specialise in PHP & Laravel as a pentester: "The fact that you understand both security *and* the frameworks I’m building with is such a big advantage over other firms that I’ve worked with." 🥰

Recently finished an audit for one of my oldest clients, this was #5! 🕵️ By far the most rewarding part of my job is working with the same clients each year, seeing their apps grow, and their commitment to security strengthen. It's not just a compliance checkbox, it's part of their culture.

Laravel Security Audits and Penetration Tests – Stephen Rees-Carter

Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!

valorinsecurity.com

Nobody cares about security until they suddenly care about nothing else... A breach, a near miss, an awkward client question, and it's suddenly top priority! Get ahead. I do Laravel Security Audits & Pentests, ideally on a quiet day, not the worst one. 🕵️ valorinsecurity.com

Laravel Security Audits and Penetration Tests – Stephen Rees-Carter

Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!

valorinsecurity.com

We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking, the attack behind tj-actions and Laravel-Lang. 😈 securinglaravel.com/in-depth-ver... #Laravel

In Depth: Version Numbers Are Vanity Labels

[In Depth # 40] We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking,…

securinglaravel.com

If you've been shipping AI-written Laravel code lately (and let's be honest, you probably have), it's worth getting a human to actually read it! Reach out for an Audit/Pentest for the parts of your codebase that vibed a little too hard. 🕵️ valorinsecurity.com

Laravel Security Audits and Penetration Tests – Stephen Rees-Carter

Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!

valorinsecurity.com