Sign in

Stephen Rees-Carter

@valorin.bsky.social
2.4K followers 514 following 1K posts

Friendly Hacker, Speaker, and PHP & Laravel Security Specialist.🕵️ I write securinglaravel.com and hack stuff on stage for fun. 😈 I'm found elsewhere too: pinkary.com/@valorin 🪄

PostsRepliesMedia
Stephen Rees-Carter @valorin.bsky.social · 16h
🧙
140
Stephen Rees-Carter @valorin.bsky.social · 27/09/2026
Not a bad view to write a new In Depth article. 😎 I'm doing a walkthrough of the results from Claude's security plugin on one of my projects, looking at the quality of the findings and how we can identify the real risks from the noise.
160
Stephen Rees-Carter @valorin.bsky.social · 18/09/2026
How does everyone feel about pentest findings/reports available online (behind auth), as opposed to emailed or sent via Slack/Teams? I've always been wary of putting them online, even behind auth, but I can see some benefits - especially with agents doing the remediation work.
010
Stephen Rees-Carter @valorin.bsky.social · 07/09/2026
During a recent pentest, I suddenly got hit with 403s on every request. It wasn't a WAF - it was a clever little trap one of my clients built to catch anyone poking at Livewire. Let me show you how it works. 🤓 securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: The Trap That Caught Me!
[Security Tip #135] During a recent pentest, I suddenly got hit with 403s on every request. It wasn't a WAF - it was a clever little trap one of my clients built to catch anyone poking at Livewire.…
172
Stephen Rees-Carter @valorin.bsky.social · 02/09/2026
Just scheduled my next Security Tip. Feels nice to be scheduling them in advance again, rather than posting late! 😎 This is a rather fun one too: a story from a recent pentest where the client's defences caught me!
160
Reposted by Stephen Rees-Carter
Andrew Feeney @andrewfeeney.au · 31/08/2026
How can you level up as a PHP / Laravel focused web developer in a world where software engineering becomes increasingly focused on security? Step 1: Sign up to @valorin.bsky.social's Securing Laravel newsletter. Congrats on an epic 5 years Stephen! Still some of the best content on the topic.
151
Stephen Rees-Carter @valorin.bsky.social · 31/08/2026
Yikes! I've been writing Securing Laravel for 5 years! 😲 securinglaravel.com/5-years-of-s... #Laravel
securinglaravel.com
5 years of Securing Laravel!
Yikes! I've been writing Securing Laravel for 5 years! 😲
160
Stephen Rees-Carter @valorin.bsky.social · 31/08/2026
Laravel's password helper has a great little feature you may have missed: it can generate browser-friendly password rules automatically! 🤓 securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Help Password Managers Get It Right!
[Tip #134] Laravel's password helper has a great little feature you may have missed: it can generate browser-friendly password rules automatically! 🤓
061
Stephen Rees-Carter @valorin.bsky.social · 24/08/2026
I've been struggling with mental and physical health issues for the past few years, and one of the things that really helped this year was finding a hobby away from technology where I get to work with my hands. Here's what I've been doing: pottery.valorin.net
pottery.valorin.net
Gallery - Pottery by Stephen
Handmade pottery by Stephen — every piece thrown, glazed & fired by hand.
4121
Stephen Rees-Carter @valorin.bsky.social · 21/08/2026
unserialize() looks harmless - it just rebuilds your data - but feed it the wrong string and it'll rebuild an attacker's object, quietly turning Laravel's own code into remote code execution. Let's pull a real RCE apart. 😈 securinglaravel.com/in-depth-fro... #Laravel
securinglaravel.com
In Depth: From Serialised String to RCE!
[In Depth #41] unserialize() looks harmless - it just rebuilds your data - but feed it the wrong string and it'll rebuild an attacker's object, quietly turning Laravel's own code into remote code…
071
Stephen Rees-Carter @valorin.bsky.social · 13/08/2026
Submitted my first CVEs directly to MITRE due to an unresponsive package maintainer for a very popular package that sits at #5 for a common search term on Packagist. Will be interesting to see how this goes.
060
Stephen Rees-Carter @valorin.bsky.social · 06/08/2026
Um... that's not how risks work... 🤦 This is the rubbish being peddled by big companies selling "Cyber Insurance". 😡
140
Stephen Rees-Carter @valorin.bsky.social · 06/08/2026
One of the most satisfying (and most frustrating!) parts of pentesting is spending an hour setting up the perfect PoC, composing shock-value screenshots, and writing a succinct report - only for them to spend 30 seconds making a trivial code change that fixes the issue. 😈😱
050
Stephen Rees-Carter @valorin.bsky.social · 03/08/2026
SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it safely. securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Do You Know Your SameSite Cookies?
[Tip #133] SameSite=Lax is the Laravel default, and it quietly protects you from CSRF. So why do I keep finding SameSite=None in the apps I audit? Let's talk about what it does and how to use it…
050
Reposted by Stephen Rees-Carter
Red Pill Junkie @redpilljunkie.bsky.social · 22/07/2026
Elon demanding a 'historically accurate' Odyssey is like a child demanding a historically accurate Smurfs movie.
1168
Stephen Rees-Carter @valorin.bsky.social · 23/07/2026
Received some great feedback from a client recently, and it really highlights why I specialise in PHP & Laravel as a pentester: "The fact that you understand both security *and* the frameworks I’m building with is such a big advantage over other firms that I’ve worked with." 🥰
040
Stephen Rees-Carter @valorin.bsky.social · 20/07/2026
What do you get when you combine an API, SameSite=None, and a Session cookie? securinglaravel.com/in-depth-thr... #Laravel
securinglaravel.com
In Depth: Three Reasonable Decisions, One Critical Vulnerability
[In Depth #41] What do you get when you combine an API, SameSite=None, and a Session cookie?
011
Stephen Rees-Carter @valorin.bsky.social · 10/07/2026
Working on a fun In Depth article for Securing Laravel at the moment. 😈 The tagline is: What do you get when you combine an API, SameSite=None, and a Session cookie? Any guesses?
110
Stephen Rees-Carter @valorin.bsky.social · 02/07/2026
Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting. securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Have You Heard Of Slopsquatting?
[Tip #132] Your AI agent hallucinates a package name, confidently installs it, and keeps working - except an attacker registered that exact name, packed with malware. Welcome to slopsquatting.
041
Stephen Rees-Carter @valorin.bsky.social · 01/07/2026
Recently finished an audit for one of my oldest clients, this was #5! 🕵️ By far the most rewarding part of my job is working with the same clients each year, seeing their apps grow, and their commitment to security strengthen. It's not just a compliance checkbox, it's part of their culture.
valorinsecurity.com
Laravel Security Audits and Penetration Tests – Stephen Rees-Carter
Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!
110
Stephen Rees-Carter @valorin.bsky.social · 22/06/2026
Updating packages used to be a no-brainer, but now you need to be careful. Updates may be malicious. But not updating leaves vulns unpatched. So what do you do??? 🤷 securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Safely Updating Dependencies
[Tip #131] Updating packages used to be a no-brainer, but now you need to be careful. Updates may be malicious. But not updating leaves vulns unpatched. So what do you do??? 🤷
040
Stephen Rees-Carter @valorin.bsky.social · 15/06/2026
Things Claude says... > Is that concerning? For local files it's not a vuln — it's theater > Is it TOFU? No — weaker than TOFU Ouch.
110
Stephen Rees-Carter @valorin.bsky.social · 11/06/2026
Nobody cares about security until they suddenly care about nothing else... A breach, a near miss, an awkward client question, and it's suddenly top priority! Get ahead. I do Laravel Security Audits & Pentests, ideally on a quiet day, not the worst one. 🕵️ valorinsecurity.com
valorinsecurity.com
Laravel Security Audits and Penetration Tests – Stephen Rees-Carter
Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!
031
Stephen Rees-Carter @valorin.bsky.social · 08/06/2026
We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking, the attack behind tj-actions and Laravel-Lang. 😈 securinglaravel.com/in-depth-ver... #Laravel
securinglaravel.com
In Depth: Version Numbers Are Vanity Labels
[In Depth # 40] We trust version numbers to mean a specific, fixed release - but they're really just labels pointing at a commit, and an attacker can quietly move them. Let's dig into tag hijacking,…
030
Stephen Rees-Carter @valorin.bsky.social · 04/06/2026
If you've been shipping AI-written Laravel code lately (and let's be honest, you probably have), it's worth getting a human to actually read it! Reach out for an Audit/Pentest for the parts of your codebase that vibed a little too hard. 🕵️ valorinsecurity.com
valorinsecurity.com
Laravel Security Audits and Penetration Tests – Stephen Rees-Carter
Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!
011
Stephen Rees-Carter @valorin.bsky.social · 01/06/2026
I've got some capacity opening up over the next few months, so If you've been meaning to get a security audit / pentest done on your Laravel app - now is the time! 🕵️ 👉 DM or valorinsecurity.com
valorinsecurity.com
Laravel Security Audits and Penetration Tests – Stephen Rees-Carter
Looking for a Laravel Security Audit and Pentest? I'm Stephen Rees-Carter and I'm excited to work with you to secure your site, and keep it safe!
010
Stephen Rees-Carter @valorin.bsky.social · 01/06/2026
With Supply Chain Attacks, you often don't realise you've been compromised until it's already too late. And yet Canary Tokens - exactly the early warning you want - are hardly mentioned. They let you know the moment someone's sniffing around. securinglaravel.com/security-tip...
securinglaravel.com
Security Tip: Canary Tokens
[Tip#31] These are my favourite simple security trick to let you know if someone is poking around in your stuff.
072
Stephen Rees-Carter @valorin.bsky.social · 29/05/2026
I may have gone to Japan and spent more time looking for these than sightseeing... maybe... (Technically I went sightseeing while looking for these, so it counts as sightseeing time, right?)
010
Reposted by Stephen Rees-Carter
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Stephen Rees-Carter
Daniel Newns @dannewns.bsky.social · 26/05/2026
It's apt then that in my inbox today is a email from @valorin.bsky.social with his latest security tip - securinglaravel.com/security-tip... and then the release of Laravel Moat by @nunomaduro.com - laravel.com/blog/moat-a-...
securinglaravel.com
Security Tip: Secure Your Repositories with Laravel Moat
[Tip #130] Laravel Moat is a new tool that assesses the security posture of your GitHub repositories and recommends ways to tighten the controls protecting them.
122
Stephen Rees-Carter @valorin.bsky.social · 26/05/2026
Laravel Moat is a new tool that assesses the security posture of your GitHub repositories and recommends ways to tighten the controls protecting them. github.com/laravel/moat securinglaravel.com/security-tip... #Laravel
github.com
GitHub - laravel/moat: Moat reviews the security posture of your GitHub organization and repositories, then surfaces recommendations to consider.
Moat reviews the security posture of your GitHub organization and repositories, then surfaces recommendations to consider. - laravel/moat
171
Stephen Rees-Carter @valorin.bsky.social · 28/04/2026
I love Signed URLs, but there is one very subtle trap you can accidentally fall into... securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: The Signed URL Trap
[Tip #129] I love Signed URLs, but there is one very subtle trap you can accidentally fall into...
181
Stephen Rees-Carter @valorin.bsky.social · 18/04/2026
Livewire's Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈 securinglaravel.com/in-depth-don... #Laravel
securinglaravel.com
In Depth: Don't Trust Public Livewire Properties
[In Depth #39] Public Properties may look like PHP class properties, but they're really hidden form fields, just waiting for your input... 😈
193
Reposted by Stephen Rees-Carter
MadeWithLaravel @madewithlaravel.com · 13/04/2026
On the Securing Laravel blog, @valorin.bsky.social explores Laravel security concepts & techniques 🔐 - madewithlaravel.com/securing-lar...
011
Reposted by Stephen Rees-Carter
Chuck Wendig @chuckwendig.bsky.social · 13/04/2026
Again, if you have a Substack, the best time to switch away was months ago -- but today's the second best time.
161563580
Stephen Rees-Carter @valorin.bsky.social · 18/03/2026
Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data? securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Stop Putting Actions on GET Requests!
[Tip #128] Do you know the difference between GET and POST requests, and why it's so important that GET requests only ever retrieve data?
080
Stephen Rees-Carter @valorin.bsky.social · 12/03/2026
As Laravel's friendly hacker, I feel it is my duty to inform everyone that Laravel v11 is no longer supported! 😱 ❌ Bug fixes (they stopped 6 months ago) ❌ Security fixes (they stop today!) Have you upgraded yet? laravel.com/docs/release... #Laravel
laravel.com
Release Notes | Laravel 12.x - The clean stack for Artisans and agents
Laravel is a PHP web application framework with expressive, elegant syntax. We’ve already laid the foundation — freeing you to create without sweating the small things.
074
Stephen Rees-Carter @valorin.bsky.social · 09/03/2026
Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access. securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Your JWT Might Be a Forever Key!
[Tip #127] Without an `exp` claim, a JWT can remain valid forever, turning a leaked token into permanent access.
033
Stephen Rees-Carter @valorin.bsky.social · 02/03/2026
Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error. securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: Validate Config at Boot
[Tip #126] Rather than checking for essential config when it's used, throw the checks in your Service Provider - you'll know about configuration failures before your users get a weird error.
050
Stephen Rees-Carter @valorin.bsky.social · 25/02/2026
PSA for @statamic.com folks - update your sites ASAP! ⚠️ A CRITICAL vuln was discovered that allows full account takeover via password resets! 😱 All the details: cvereports.com/reports/CVE-...
github.com
CVE-2026-27593 - GitHub Advisory Database
Statamic is vulnerable to account takeover via password reset link injection
096
Stephen Rees-Carter @valorin.bsky.social · 24/02/2026
I am determined to get back to @laravellive.dk this year, so if you have a dev team or a meetup in EU or UK and want me to run a workshop or give a talk in August, let me know!
010
Stephen Rees-Carter @valorin.bsky.social · 23/02/2026
You can't trust an email address you haven't verified, so why are you storing them in your database? securinglaravel.com/in-depth-ema... #Laravel
securinglaravel.com
In Depth: Email Verification Isn't as Simple as You Think
[In Depth #38] You can't trust an email address you haven't verified, so why are you storing them in your database?
150
Stephen Rees-Carter @valorin.bsky.social · 14/02/2026
routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one? securinglaravel.com/security-tip...
securinglaravel.com
Security Tip: Consider All Routes, Not Just Web!
[Tip #125] routes/web.php is boring and reliable, and routes/api.php is fancy, but have you forgotten one?
061
Stephen Rees-Carter @valorin.bsky.social · 05/02/2026
I know I say this all the time (especially on stage!), but apparently not everyone heard me, so here we go again... securinglaravel.com/security-tip...
securinglaravel.com
021
Stephen Rees-Carter @valorin.bsky.social · 04/02/2026
It's been 4 months, a lot has happened, but I'm finally back to writing securinglaravel.com! New Security Tip coming out in a few hours...
securinglaravel.com
Securing Laravel
The essential security resource for Laravel developers.
090
Stephen Rees-Carter @valorin.bsky.social · 18/11/2025
Exhausted after #LaraconAU last week, but excited by how it all went! I was so proud of everyone in my workshop on Wednesday - everyone had a go, and the excitement in the room as they hacked through challenges made it all worth it.
150
Stephen Rees-Carter @valorin.bsky.social · 17/10/2025
Haven't bought tickets to my Pre-@laracon.au Security Workshop yet?! 😲 I'll be locking in numbers early next week, so get your ticket TODAY or reach out to me directly. ⌛ This is your final warning... ⏰ events.humanitix.com/lets-hack-pr...
events.humanitix.com
"Let's Hack!" Pre-Laracon Security Workshop
Attending Laracon AU? Come along to
001
Stephen Rees-Carter @valorin.bsky.social · 08/10/2025
"Let's Hack!", my Pre-Laracon Security Workshop is just FIVE weeks away! 🎉 (So is @laracon.au... but let's be honest, priorities.) Only 11 tickets left, & I need to confirm numbers with the venue, so if you've been thinking about it, now's the time! 👉 events.humanitix.com/lets-hack-pr...
events.humanitix.com
"Let's Hack!" Pre-Laracon Security Workshop
Attending Laracon AU? Come along to
011
Stephen Rees-Carter @valorin.bsky.social · 29/09/2025
If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands? 🤔 securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: How Should APIs Respond to HTTP?
[Tip #123] If an API client tries to connect via unencrypted HTTP, what should your API do: redirect to HTTPS, disable HTTP, offer a swift rebuke, or take matters into it's own hands?
131
Stephen Rees-Carter @valorin.bsky.social · 25/09/2025
Cookies come in many shapes and sizes, and with multiple attributes just to confuse you... Have you ever wondered what the humble HttpOnly attribute actually does? securinglaravel.com/security-tip... #Laravel
securinglaravel.com
Security Tip: What Is An HttpOnly Cookie?
[Tip #86] Cookies come in many shapes and sizes, and with multiple attributes just to confuse you... Have you ever wondered what the humble HttpOnly attribute actually does?
160