Skip to content
View al4an444's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report al4an444

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
al4an444/README.md
Alan Ortega Álamo — Security researcher

Alan Ortega Álamo — self-taught security researcher. I look for vulnerabilities in widely used software and disclose them responsibly. Open to junior roles in application security, vulnerability research or security engineering — Madrid or remote.

Website · LinkedIn · Instagram · alanortega7312@gmail.com

Findings

Vendor Finding Severity Status
01 Google · grpc-go Authentication bypass in the xDS RBAC engine: the authenticated-principal matcher fell through from URI/DNS SANs to the certificate's Subject DN. Credited in the release notes. CVSS 7.5 Fixed · v1.81.1 · PR #9111
02 Google · protobuf-go prototext recursion limit bypassed on the unknown-field skip path, crashing the process with an unrecoverable stack overflow. Reported it and authored the fix. Denial of service Merged · CL 774741
03 Microsoft · Azure msi-acrpull The ACR server field of an AcrPullBinding was not restricted to trusted registry domains, so the controller could send its Azure (ARM) bearer token to an attacker-controlled endpoint. Confirmed by MSRC. Important · Information disclosure Fixed · PR #129
04 NVIDIA · PSIRT — High Reproduced · under review

Open reports stay at vendor, severity and status until the vendor publishes.

Case study — ZeroLogon (CVE-2020-1472). My vocational school's domain controller was missing the August 2020 updates. I demonstrated the impact, stopped at proof, kept no data, reported it and helped remediate. Read the writeup →

Built

Project What it does Stack
phishguard Explainable phishing detection for URLs and e-mails: heuristic rules plus an ML model, CLI, REST API and web UI. Everything runs locally. Python · FastAPI · scikit-learn
ghosttalk End-to-end encrypted, zero-knowledge chat. TypeScript · React · Supabase · Web Crypto API
shutdown-restore Windows service that creates a restore point on every shutdown, bypassing the 24 h limit and rotating old backups. C++ · Windows services

Education & certifications

  • HND in Network & Systems Administration (ASIR) — ILERNA Online · 2025–2027, in progress
  • Vocational degree in Microcomputer Systems & Networks (SMR) — 2023–2025
  • Introduction to the Threat Landscape 3.0 — Fortinet Training Institute · Apr 2026
  • Introduction to Cybersecurity — Cisco Networking Academy · Apr 2026

Pinned Loading

  1. shutdown-restore shutdown-restore Public

    Automated C++ Windows Service that creates a system restore point on shutdown, bypassing the 24h limit and rotating old backups.

    C++ 2

  2. ghosttalk ghosttalk Public

    A secure, end-to-end encrypted (E2EE) zero-knowledge chat application built with React, Supabase, and the Web Crypto API.

    TypeScript 1