Skip to content
View stvnhrlnd's full-sized avatar

Organizations

@Full-Hack-Developer

Block or report stvnhrlnd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
stvnhrlnd/README.md

๐Ÿฉ Stvn Hrlnd (He/Him)

Hi ๐Ÿ‘‹, I'm Steven, a software developer and offensive security professional based in Scotland ๐Ÿด๓ ง๓ ข๓ ณ๓ ฃ๓ ด๓ ฟ. Below are some of the more interesting repos you will find on my GitHub profile.

๐Ÿš€ Current Projects

๐Ÿง Vulnerability Research

  • UmbProfile CSRF PoC - Proof of concept for a cross-site request forgery in Umbraco member profiles.
  • UmbRegister-Spoofer - A Python script to create arbitrary members in Umbraco by exploiting the auto-routed surface controllers that Umbraco ships with.

๐Ÿ—ฃ๏ธ Talks/Workshops

๐Ÿ”— Other Links

Pinned Loading

  1. DVUA DVUA Public

    Damn Vulnerable Umbraco Application

    CSS 1

  2. web-hacking-101 web-hacking-101 Public

    Course materials for the Web Hacking 101 workshop delivered at Codegarden 2025.

    HTML 5 2

  3. Full-Hack-Developer/fr1end1y Full-Hack-Developer/fr1end1y Public

    A starter kit for Umbraco-powered Eleventy sites.

    JavaScript

  4. donutsec.fun donutsec.fun Public

    My blog site.

    JavaScript

  5. UmbProfile-CSRF-PoC UmbProfile-CSRF-PoC Public

    Proof of concept for a cross-site request forgery in Umbraco member profiles.

    JavaScript 1

  6. UmbRegister-Spoofer UmbRegister-Spoofer Public

    A Python script to create arbitrary members in Umbraco by exploiting the auto-routed surface controllers that Umbraco ships with.

    JavaScript 1