Ben Marsh
Ben Marsh

Ben Marsh

Independent security researcher.

Hey 👋

You're probably here because you received an unsolicited security email from me and wanted to make sure I'm a real person.

Or maybe someone pointed you here.

Either way, welcome.

I spend a good portion of my time identifying security issues, responsibly disclosing them to affected organizations, and helping improve the security of applications and infrastructure.

I believe security research should leave systems safer than they were found.

What I do

Responsible Security Disclosure

I identify and privately report security vulnerabilities to affected organizations before they can be exploited.

My reports may include (but are not limited to):

Exposed secrets and credentials Database and storage misconfigurations API and authentication issues Cloud infrastructure exposures Source code leaks Payment and blockchain security issues General web application vulnerabilities

If you've received an email from me regarding a security issue, it was sent in good faith with the intention of helping you secure your systems.

I'm also happy to answer follow-up questions or assist in validating and mitigating any issue I've reported.

Security Reviews & Audits

I provide independent reviews for:

  • Web applications
  • APIs
  • Smart contracts
  • Internal tools
  • Infrastructure configurations

Whether you're preparing for launch or simply want another set of eyes on your systems, I'm happy to help.

Software Engineering

Outside of security research, I build software.

Backend systems Automation Developer tooling Blockchain applications Distributed systems Full-stack web development

Security and engineering complement each other. Building software helps me understand how vulnerabilities happen, while security research helps me build more resilient systems.

My Principles

  • Respect privacy.
  • Minimize access.
  • Never disclose vulnerabilities publicly before giving affected parties an opportunity to fix them.
  • Be professional.
  • Leave systems better than I found them.

Need to verify a disclosure?

If you've received a vulnerability report from me and would like to verify its authenticity, feel free to reach out using any of the contact methods below.

If you have questions about a report, need clarification, or would like assistance reproducing or mitigating an issue, I'm always happy to help.

Contact

Website (You're already here 🙂)

Thank you for taking security seriously.
Have a great day, and I hope the next email you receive from me is one you'd rather not need. 😄