Blind pentest round 2 against v0.2.1 on k3s #80

Closed
opened 2026-09-09 14:42:59 +00:00 by poslop · 0 comments
Owner

Second blind black-box pentest, this time against v0.2.1 (all round-1 fixes merged: #63 delete auth, #58 burn race atomic claim, #65 listing leak, #66 admin ratelimit, #59/#76 security headers, #74/#78 validation).

Same rules as #61: no source access, no knowledge of prior findings beyond what an external attacker could learn, live HTTP surface only, capped request volume (~2-3k), live-verify every finding with repro, file findings as issues.

Second blind black-box pentest, this time against v0.2.1 (all round-1 fixes merged: #63 delete auth, #58 burn race atomic claim, #65 listing leak, #66 admin ratelimit, #59/#76 security headers, #74/#78 validation). Same rules as #61: no source access, no knowledge of prior findings beyond what an external attacker could learn, live HTTP surface only, capped request volume (~2-3k), live-verify every finding with repro, file findings as issues.
Sign in to join this conversation.