I read software like an attacker and build it like production depends on it.
Security is not a checklist. It is the distance between what a system promises and what its boundaries actually enforce.
Offensive security
Manual analysis, controlled exploitation, attack-path validation and reverse engineering.
vuln research / exploit dev / reversingApplication security
Secure code review, threat modeling, authorization analysis, hardening and remediation support.
code review / threat modeling / authzSecure engineering
Production backend architecture, distributed systems, server authority and abuse resistance.
distributed systems / anti-abuse- role
- senior engineer, cto, offensive security
- experience
- 12+ years, since 2014
- base
- brazil, remote, utc-3
- status
- open to select engagements
Evidence before claims.
Assigned CVEs, accepted reports and independent proof-of-concept work. Every entry links to its public record.
File Browser, symlink scope bypass
Scoped users, and some unauthenticated share recipients, could escape the enforced directory boundary through symlink handling.
Gitea, Git LFS authorization bypass
A cross-repository flaw let users without source-repository permission retrieve private LFS objects.
Symlink traversal to git hook injection
A path-boundary flaw in gh run download allowed writes outside the destination and could plant an executable git hook.
WooCommerce Designer Pro, unauthenticated upload to RCE
Independent, reproducible proof of concept for an unauthenticated file upload leading to remote code execution.
Names identify the program or affected ecosystem. They do not imply employment, endorsement or partnership.
Systems in front of millions.
Live products. Real scale.
Atlantic Interactive
Technology direction, architecture, engineering standards, hiring, security, performance and LiveOps delivery.
Spong
Production updates, systems optimization, abuse prevention and continuous evolution of live experiences.
Wendigo Studios
Gameplay and backend systems built around server authority and maintainable delivery.
Chabungus LLC
Software and game systems for production projects and scalable delivery.
Lost Creative
Backend and gameplay-facing systems designed for stability and long-term maintenance.
BlockTurns
Game development and backend delivery in a large Roblox publishing ecosystem.
Built in the open. Built for production.
Defensive path handling against traversal, symlink escape, Zip Slip and TOCTOU.
Repeatable attack-surface mapping, crawling, enumeration and fingerprinting.
Automated SQL injection detection with payload-driven validation.
High-performance client-server networking and compact state synchronization.
- languages
- Python, TypeScript, Rust, Go, C, C#, Lua, Luau, SQL
- infrastructure
- Linux, Docker, Kubernetes, Terraform, Cloudflare, PostgreSQL, Redis
- security
- Burp Suite, mitmproxy, Frida, Ghidra, Semgrep, Nmap, Wireshark
- specialization
- Backend architecture, distributed systems, server authority, anti-cheat, reverse engineering
A.S.I.A
Attack Surface Intelligence & Assurance
My independent security practice. Scoped assessments, reproducible evidence and remediation your engineers can act on. Security without theater.
visit a.s.i.awnk.sh
Built together, kept separate.
A collaborative project with a partner, presented apart from my solo research, A.S.I.A and engineering work.
visit wnk.shSerious systems. Serious security.
Available for senior engineering, offensive security, AppSec and focused research engagements.
m2hczs@proton.me