Authentication
Login, recovery, MFA, token lifecycle, session state, and identity verification paths.
Authentication. Authorization. Business logic. Tenant boundaries.
I am Judel Palaca, also known as pal0x. I research practical vulnerabilities in modern web applications, with emphasis on identity, access control, cross-tenant isolation, and complex workflow abuse.
My work prioritizes realistic attack paths over noisy checklist findings. The objective is to understand how a system behaves, identify where its assumptions fail, and demonstrate impact in a controlled and reproducible way.
Login, recovery, MFA, token lifecycle, session state, and identity verification paths.
Object access, privilege boundaries, role enforcement, tenant separation, and cross-account behavior.
Workflow integrity, hidden state transitions, chained actions, and assumptions that fail under adversarial use.
Inspect frontend behavior, API surfaces, account roles, state transitions, and feature boundaries before testing.
Use controlled accounts and resources to verify exploitability without overstating severity or relying on assumptions.
Deliver concise steps, clear evidence, impact analysis, and remediation guidance that engineering teams can act on.
Published security research and public contributions across real products and codebases.
Reported unsafe local secret writes in the Capgo CLI. Attacker-controlled repository symlinks could redirect writes to arbitrary files, while global build credentials were created with overly permissive file permissions. GitHub reviewed the advisory and lists affected versions before 7.84.6.
VIEW GITHUB ADVISORY →Cleaned singularize-related dead code warnings and aligned the change with feature-gated build requirements.
VIEW PULL REQUEST →Added configurable max_body_size support and documented request-size controls.
VIEW PULL REQUEST →Improved markdown rendering performance by lazy-loading syntax highlighting only when required.
VIEW PULL REQUEST →Added appropriate aria-label and aria-pressed behavior to improve the web search toggle for assistive technology.
VIEW PULL REQUEST →I provide focused reviews for startups, SaaS applications, account systems, administrative panels, and sensitive workflows. Engagements are intentionally narrow and centered on realistic attack surfaces.
Provide the application type, preferred scope, testing environment, and any important restrictions.