Stephen Rees-Carter :laravel:

Friendly Hacker, Speaker, and PHP & Laravel Security Specialist.🕵️
I hack stuff on stage for fun. 😈
I used to be found at: infosec.exchange/@valorin
#searchable

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-06-06

Starting to lock in details for the Pre-Laracon Security workshop in Brisbane! 🎉

It'll be the morning of Wednesday 12th November - the day before Laracon AU, at a venue really close to the conference.

I'll get ticket sales open soon, but sign up at workshop.valorinsecurity.com/ to keep informed.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-06-04

It's incredibly common to find hardcoded domains used for identifying admins, however this also makes it trivial to escalate privileges to admin! 😈

securinglaravel.com/security-t
#Laravel

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-06-04

"Don't Roll Your Own Crypto" applies to password generators too! It's way too easy to unknowingly lower your entropy by trying to be clever... 😱

securinglaravel.com/security-t #Laravel

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-06-03

It may be tempting to reach for env() outside your config files, but you may be introducing subtle bugs, or exposing your app to compromise... 😱

securinglaravel.com/security-t #Laravel

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-29

@bobmagicii @outofcontrol

Oooh, yes. This would be a great way to do it. Sometimes you do need that info, but really only once.

When I did WordPress site cleaning, our toolkit was auto-deleting. We'd upload the script, use it to extract all the files and metadata, and when it was done, the file would remove itself.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-29

@outofcontrol Painless to abuse too. 😈

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-28

It may seem like a harmless debugging tool, with a bunch of boring config values and version numbers, but phpinfo() is a goldmine of sensitive data - even when it's "protected" in an admin account! 😈

securinglaravel.com/security-t #Laravel

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-28

So many spinning plates at the moment, between trying to organise workshops, trips, sponsors, audit/pentest clients, etc... 🥴

To keep up with all I'm doing, sign up to securinglaravel.com. The "Appendices" after each email has everything coming up, and any opportunities. 🙏

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-27

On the subject of Laravel Security Workshops, any companies in the EU or UK interested in an in-person workshop for their team? I'm hoping to book a few around Laravel Live Denmark. 🤓

I've transformed "Th1nk Lik3 a H4cker" into a much bigger, fully-interactive, workshop format! 😈

#Laravel #laravellivedk

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-27

Excited to report that I've had a lot of interest for a Laravel Security Workshop at Laracon AU, so I'm looking into venues for a half-day on Wed morning (12th Nov), so you just have to come a day early! 🎉

If you're interested and want to keep in the loop, I've popped up an announcements mailing list: workshop.valorinsecurity.com

#Laravel #LaraconAU

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-26

@bobmagicii I think it works for shows that have limited scope, such as Bridgerton - it would've suffered if it didn't have a single focused story.

But for stories with a big scope like LOTR, WOT, Star Gate, Star Trek, etc, they need that space to explore.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-26

@bobmagicii Yeah, and they had a plenty of time to explore their "world", with lots of tangents and side plots. Rather than every minute being focused on the final endgame.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-26

@bobmagicii Stargate was such a fun show!

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-25

Ok Aussie & NZ friends, would anyone be interested in coming to a half or full day security workshop in Brisbane the week before #LaraconAU (i.e. Mon, Tues, or Wed)? 🤓

If there is enough interest, I'll start looking for a venue and figure out pricing, etc.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-24

I miss the days when TV shows had more episodes, smaller budgets, and space to breathe. Wheel of Time was an incredible show, but 8 eps per season wasn't enough, and the "expectations of success" were set too high. 😭

What am I going to alternate years with Rings of Power now?

#TheWheelOfTime

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-23

@standaniels Definitely one of the joys of this job. 😎

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-23

@me Hehe, indeed.

Honestly, it's a fairly predictable bypass. It sounds a lot cooler if I'm mysterious than actually coming out and saying it.

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-22

Just bypassed CloudFlare Access on a client's site! 😈

Ask Me Anything!

Note, my NDA prevents me from answering anything even vaguely relevant, but feel free to ask... 🤣

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-21

I've been considering this for a while, so it's time to throw it out into the world...

Securing Laravel is now open to sponsorships! 🎉

Your company can sponsor my weekly Security Tips, supporting my work in improving security within the Laravel and PHP communities .

👉 securinglaravel.com/sponsor

Stephen Rees-Carter :laravel:valorin@phpc.social
2025-05-21

It's comments like these that make all the work I put into my big articles like securinglaravel.com/in-depth-a so worth it! 🥰

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst