John Carroll
Topic

AppSec

Application Security

Ghosted.
Exploitation

Ghosted.

Ghosted Domains coming to haunt you, one more check for your scanners, vendor assurance, OSINT, Supply chain, Appsec and all the rest of that good stuff.

19 Sep 2025 · 23 min read
Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy
Random

Securing Ghost Blog Authentication with Cloudflare's ZeroTrust Access Policy

How to implement MFA in Ghost Blog with Cloudflare's Zerotrust Access Policy.

1 Sep 2023 · 5 min read
OWASP Top 10 - 2021
AppSec

OWASP Top 10 - 2021

This post is as much as an internal sit-rep as it is one for others to witness, share and challenge, I'm trying to understand the Top10's value eleven years on, the current top10 (2021) is in draft and open for comment, I've put my comments here, as well as the opening to this conversation on github

3 Dec 2022 · 4 min read