Skip to content
View AlanNewberry's full-sized avatar
:shipit:
Focusing
:shipit:
Focusing

Block or report AlanNewberry

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AlanNewberry/README.md

Alan Newberry

Offensive Security · Application Security · Software Engineering

Website LinkedIn Hack The Box

Software engineer with 3+ years of professional experience building web, mobile, and SaaS products. I focus on offensive security and application security, combining an attacker's perspective with practical knowledge of authentication, authorization, APIs, multi-tenant data isolation, and production infrastructure.

I build security tooling and reproducible proof-of-concepts for authorized research and lab environments.

Selected security research

Project Focus
CVE-2026-4480 — Samba print command injection Unauthenticated command injection through Samba's %J print job substitution
CVE-2026-3888 — snap-confine privilege escalation Local privilege escalation through a race condition and loader hijacking
AD CS ESC1 template cloning Active Directory Certificate Services privilege escalation
Gitea/Gogs symlink to RCE .git/config poisoning through repository-content APIs
PyYAML to AWS CodeBuild escape Unsafe deserialization chained with a privileged container escape
SOAP/WCF XXE file disclosure Out-of-band XXE exploitation and server-side file disclosure

Security tooling

Project Description
Vandal Web security scanner for reflected XSS, SQL injection, security headers, subdomain discovery, and historical URL collection
Luna Modular REST API security scanner covering IDOR, authentication, SQL injection, XSS, HTTPS, and structured JSON reporting
Astral Sniffer Packet capture and traffic analysis with protocol filters, PCAP export, and CSV/JSON statistics
Good Luck Multithreaded SYN, TCP, and UDP port scanner with banner grabbing and JSON output
Pentest Reports Web and API penetration-testing report templates using OWASP, PTES, CWE, and CVSS v3.1

Technical focus

Security Web and API security, vulnerability research, exploitation, privilege escalation, network analysis, DFIR
Engineering Authentication and authorization, REST APIs, RBAC, Row Level Security, multi-tenant systems, secure SDLC
Languages Python, Bash, Go, JavaScript/TypeScript, Kotlin, Swift
Infrastructure Docker, PostgreSQL, Redis, Supabase, Cloudflare, Vercel, Nginx

Product engineering

  • Vulnex — Cybersecurity SaaS for breach exposure, compromised credentials, and typosquatting monitoring.
  • Vandal Health — Multi-tenant healthcare SaaS using RBAC, Row Level Security, REST APIs, and containerized deployment.
  • Healthcare interoperability API (private repository) — OAuth2 Client Credentials, JWT, tenant isolation, Redis rate limiting, and security tests for exchanging sensitive clinical data.
  • Fix! — Native iOS and Android applications with Firebase authentication, APNs/FCM, Mercado Pago, and production store releases.
  • Lightmoon — Social platform with Google OAuth, profiles, posts, comments, and reactions.
  • RACE.COM — Android application communicating with motorsport scales through Bluetooth Low Energy.

Most professional source code is private due to client confidentiality.

Labs and continuous training

Hack The Box: Hacker rank · Level 53 (Professional)
Progress: 35 machines · 41 challenges · 12 Sherlocks

Selected Hack The Box work

Machines

  • Hard: Nimbus, Snapped, Ghostlink, Checkpoint
  • Medium: Abducted, DanglingTree, Bedside, Layover, MakeSense, SmartHire, Principal, FireFlow, DevHub, Blurry
  • Easy: Cohort, Touch, Management, TwoMillion, Kobold, Silentium, Orion, Nexus, Paperwork, Enigma, Connected, Reactor, Bashed, Irked, PermX, Networked, Luanne, Cap, Spectra, Lame

Challenges

  • Web: ReactOOPS, OpenSecret, Space Explorer, Sp00ky Theme, WayWitch, Armaxis, OnlyHacks, Evaluative, Spookifier, Flag Command, SpookyPass
  • DFIR/Forensics: Primed for Action; UFO-1, Operation Blackout 2025: Phantom Check, CrownJewel-1/2, Reaper, Noxious, Campfire-1/2, Dream Job-1, BFT, Unit42, Brutus
  • Additional work across crypto, reversing, OSINT, hardware, satellite, and quantum challenges

Additional practical training through Hack4u in ethical hacking, offensive Python, Linux administration, and professional Linux environments. English: B1 conversational, B2 reading/writing.

Contact

Security tools and proof-of-concepts in this profile are intended exclusively for authorized testing, research, and educational environments.

Pinned Loading

  1. CVE-2026-4480-samba-print-command-injection-rce CVE-2026-4480-samba-print-command-injection-rce Public

    Exploit para CVE-2026-4480: inyeccion de comandos en la variable %J del print command de Samba para RCE sin autenticacion via spoolss.

    Python 2

  2. adcs-esc1-clone-certificate-template-privesc adcs-esc1-clone-certificate-template-privesc Public

    Clona un template de certificado vulnerable a ADCS ESC1 para escalar privilegios en Active Directory.

    Python 1

  3. CVE-2026-3888-snap-confine-privilege-escalation CVE-2026-3888-snap-confine-privilege-escalation Public

    Exploit para CVE-2026-3888: race condition en snap-confine con hijack del loader para escalar a root en Linux.

    C 1

  4. gitea-gogs-symlink-git-config-rce gitea-gogs-symlink-git-config-rce Public

    RCE en Gitea/Gogs envenenando .git/config a traves de un symlink via la API de contenidos (core.sshCommand).

    Python 1

  5. pyyaml-unsafe-deserialization-rce-aws-codebuild-escape pyyaml-unsafe-deserialization-rce-aws-codebuild-escape Public

    Cadena de RCE por deserializacion insegura de PyYAML y escape de contenedor privilegiado AWS CodeBuild via core_pattern.

    Python 1

  6. soap-wcf-xxe-out-of-band-file-disclosure soap-wcf-xxe-out-of-band-file-disclosure Public

    XXE out-of-band sobre servicios SOAP/WCF de .NET para lectura y exfiltracion de archivos del servidor.

    Python 1