Hey, I am Greg
I am an independent developer, and OSCP-certified penetration tester.
You can hire me for
Ruby and Ruby on Rails
development, and exploit development.
I contribute to open-source projects as much as I can. You can view all my contributions on my GitHub profile, but here are a few of them:
Conference talks
Talks and workshops I have given at Ruby and Rails conferences.
Podcast appearances
- Technology for Humans: Greg Molnar reinteractive Listen to Technology for Humans: Greg Molnar
- From Breaking PHP to Protecting Rails The Expert Bench Listen to From Breaking PHP to Protecting Rails
- Essential Tools, Updates, and Strategies in Rails Eight Ruby Rogues Listen to Essential Tools, Updates, and Strategies in Rails Eight
- Ruby Dev Summit — Greg Molnar Ruby Rogues Listen to Ruby Dev Summit — Greg Molnar
- Security on Rails IndieRails Listen to Security on Rails
- Uncovering Unknown Security Issues with Penetration Testing Ruby Rogues Listen to Uncovering Unknown Security Issues with Penetration Testing
- Server-Side Request Forgery with Greg Molnar Ruby Rogues Listen to Server-Side Request Forgery with Greg Molnar
- A New Rails Conference! No More ArgumentError for Long Index Names The Rails Changelog Listen to A New Rails Conference! No More ArgumentError for Long Index Names
Cyber security certifications
OffSec Certified Professional
OSCP is considered to be more technical than other ethical hacking certifications and is one of the few that requires evidence of practical penetration testing skills.
Blue Team Level 1
Earners of the Blue Team Level 1 Certification have showcased their practical ability to defend networks and systems from cyber threats through technical and hands-on defensive cybersecurity training. They have knowledge and ability across 5 security operations domains which include Phishing Analysis, Digital Forensics, Threat Intelligence, SIEM, and Incident Response.
- My HackerOne profile: https://hackerone.com/gregmolnar
- Ruby Events XSS
- Phlex XSS(CVE-2024-32463): https://github.com/phlex-ruby/phlex/security/advisories/GHSA-g7xq-xv8c-h98c
- console1984 bypasses:
- authentication-zero lack of brute-force protection
- DocuSeal MFA bypass
A few public security issues I found and reported
Buy my course!
Are you eager to elevate your security skills and safeguard your applications against cyber threats? This Rails Securitycourse is designed specifically for developers like you who aim to build robust, secure Rails applications!
Get access to my book
This book is about how to take security into account when doing a code review in a Rails app.
Develop the right mindset for Rails code security reviews
Check out my blog
Subscribe to my newsletter
Subscribe to my newsletter to get notified when I post to my blog. I regularly write about Ruby, Ruby on Rails and security topics.