Skip to content
Ben Marsh
Ben Marsh

Ben Marsh

Independent security researcher.

Hey 👋

You're probably here because you received an unsolicited security email from me and wanted to make sure I'm a real person.

Or maybe someone pointed you here.

Either way, welcome.

I spend a good portion of my time identifying security issues, responsibly disclosing them to affected organizations, and helping improve the security of applications and infrastructure.

I believe security research should leave systems safer than they were found.

What I do

Responsible Security Disclosure

I identify and privately report security vulnerabilities to affected organizations before they can be exploited.

My reports may include (but are not limited to):

Exposed secrets and credentialsDatabase and storage misconfigurationsAPI and authentication issuesCloud infrastructure exposuresSource code leaksPayment and blockchain security issuesGeneral web application vulnerabilities

If you've received an email from me regarding a security issue, it was sent in good faith with the intention of helping you secure your systems.

I'm also happy to answer follow-up questions or assist in validating and mitigating any issue I've reported.

Security Reviews & Audits

I provide independent reviews for:

  • Web applications
  • APIs
  • Smart contracts
  • Internal tools
  • Infrastructure configurations

Whether you're preparing for launch or simply want another set of eyes on your systems, I'm happy to help.

Software Engineering

Outside of security research, I build software.

Backend systemsAutomationDeveloper toolingBlockchain applicationsDistributed systemsFull-stack web development

Security and engineering complement each other. Building software helps me understand how vulnerabilities happen, while security research helps me build more resilient systems.

My Principles

  • Respect privacy.
  • Minimize access.
  • Never disclose vulnerabilities publicly before giving affected parties an opportunity to fix them.
  • Be professional.
  • Leave systems better than I found them.

Need to verify a disclosure?

If you've received a vulnerability report from me and would like to verify its authenticity, feel free to reach out using any of the contact methods below.

If you have questions about a report, need clarification, or would like assistance reproducing or mitigating an issue, I'm always happy to help.

Contact

Website(You're already here 🙂)

Thank you for taking security seriously.
Have a great day, and I hope the next email you receive from me is one you'd rather not need. 😄