~
A gallery of vulnerabilities, patches, and other contributions I've made

Or, the cumulative sum of my professional existence

Vulnerabilities
Open Source
Curios

The projects below can be summed in this philosophy: code with gleeful abandon in your free time and with brutal discipline professionally


Vulnerabilities

πŸ‘” FlowCrypt
Most of my disclosed vulnerabilities are from my current workplace, FlowCrypt. All of the bugs on FlowCrypt's Fixed Vulnerabilities docs that mention Alex are referring to me.

Ξ» Racket Stories
I found an XSS vulnerability on racket-stories.com and submitted this patch.

βš” Codewars
Codewars includes me in their Security Acknowledgements for reporting multiple stored XSS vulnerabilities.

πŸ’° GitHub
GitHub awarded me $600 after I reported a flaw in their security notification alerts

πŸ—ΊοΈ Atlassian
I won $100 for disclosing a blind, internal SSRF in Atlassian's Statuspage


Open Source

πŸ§… Tor
My patch made Torsocks compatible with Mutt and numerous other applications

πŸ”’ sslscan
Made a small improvement to the signature algorithm scanning code

🌢︎ OpenPGP Spanish Translation Team
I help translate open source cryptography tools into Spanish as part of the openpgp.org translation team

πŸ›‘οΈ libhomograph
I am the maintainer of libhomograph, a library for defending against Internationalized Domain Name homograph attacks

🧹 S3 Exif Cleaner
This simple tool iterates through every image in an S3 bucket and cleanses EXIF data

πŸ’Œ GistBlog
React component to use GitHub Gists as a free, headless CMS for blogs on static hosts like GitHub pages. NPM package and live example.

🍺 SAN Scanner
A Burp Suite app available in the BApp store that passively scans for Subject Alternate Names for pentesters and CTF players.

🚨 Email Addresses in Comments Monitor
GitHub Action to monitor comments on a repo for plaintext email addresses. Listed in GitHub Marketplace

πŸ“° HackerNews Candidates Search
Tool for recruiters to find candidates using HN monthly hiring threads. Included by HN staff in monthly hiring posts


Curios

πŸ₯Š Code Puzzles
I love code puzzles. I'm @seisvelas on Codewars, and have a Toy Problem Gallery from when I was learning frontend.

πŸ§™ Teaching
I mentor other CTF players on my HackTheBox team, and enjoy providing in-depth answers via my StackOverflow profile

πŸ›οΈ Latin
An avid medievalist, I'm proud to host and administer the only Mastodon instance serving the medieval and classical Latin communities, latin.masto.host