Skip to content
View kta1kri's full-sized avatar
  • Japan
  • 09:58 (UTC +09:00)

Sponsors

@ubicloud

Block or report kta1kri

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kta1kri/README.md

Hi, I'm kta1kri πŸ‘‹

Independent security researcher working on coordinated vulnerability disclosure.

I audit open-source projects and self-hosted software and report issues through each project's responsible-disclosure channel. Focus areas:

  • Authorization & access control β€” broken access control, IDOR, missing permission checks
  • Web & API security β€” SSRF, injection, auth/scope bypass, webhook/IPN authenticity
  • Secrets & supply chain β€” secret exposure in tooling/IaC, insecure defaults in CI/build

Profiles

  • Patchstack β€” researcher profile (published advisory: Simple Cloudflare Turnstile ≀ 1.42.1 β€” Content Injection, CVSS 6.5)
  • Intigriti β€” profile
  • HackerOne β€” profile

Projects

  • tfsensitive β€” a Go (go/ast) linter that catches a silent Terraform SDKv2 footgun: a Sensitive: true field nested inside a Computed-only TypeList/TypeSet, which SDKv2 drops so the secret lands in plan/state. MIT.

Merged security fixes (public)

I also file coordinated-disclosure reports to many other projects (kept private while under embargo) and run small security labs / PoCs for CI/CD and IaC issue patterns.

Disclosure approach

I follow coordinated vulnerability disclosure: reports go to the project's designated security channel first, I honor requested embargoes (typically up to 90 days), and I publish details only after a fix ships or the embargo ends. Reports include a concrete proof-of-concept and a suggested fix.

Support

If my work has helped your project, sponsorship funds continued security research and responsible disclosure. Thank you πŸ™

For security matters, please use the relevant project's security channel.

Popular repositories Loading

  1. chirpstack chirpstack Public

    Forked from chirpstack/chirpstack

    ChirpStack open-source LoRaWAN Network Server

    Rust

  2. trust-manager trust-manager Public

    Forked from cert-manager/trust-manager

    trust-manager is an operator for distributing trust bundles across a Kubernetes cluster.

    Go

  3. alexander-storage alexander-storage Public

    Forked from Joker1230005/alexander-storage

    πŸ—„οΈ Build scalable, S3-compatible object storage with Alexander Storage for archival, backups, and enterprise needs, all in a self-hosted solution.

    Go

  4. coinkite-tap-proto coinkite-tap-proto Public

    Forked from coinkite/coinkite-tap-proto

    SATSCARD and TAPSIGNER from Coinkite

    Python

  5. terraform-provider-ncloud terraform-provider-ncloud Public

    Forked from NaverCloudPlatform/terraform-provider-ncloud

    Terraform NaverCloud provider

    Go

  6. kta1kri kta1kri Public

    Security researcher β€” coordinated vulnerability disclosure