Final-year Cybersecurity Engineering student | C#/.NET contributor | Security researcher
I take on small, well-scoped paid C#/.NET debugging tasks, especially around logging, reproducing failures, and adding focused regression tests. I agree the scope and delivery before starting.
- Apache log4net — merged contribution: fixed silent log-event loss while
XmlConfiguratorreconfigures appenders. Merged pull request #287 - Apache Log4j2 — issue report: reported incorrect sanitization of RFC 5424 structured-data parameter names; the project merged a fix. Pull request #4073
- CVE: CVE-2026-70426, Jenkins Remoting agent-to-controller deserialization filter bypass. Jenkins security advisory
- Security research: I participate in CTFs and use TryHackMe and Hack The Box. TryHackMe · Hack The Box
- Reproduce and investigate one specific C#/.NET bug.
- Fix a scoped issue and add a regression test where practical.
- Review logging behavior and configuration, including log4net.
- Write a concise technical handover with test results.
I only perform security testing with written authorization and an agreed scope. I do not claim a fix, assessment, or production result until it has been completed and verified.
For a small task, open a GitHub issue with the expected behavior, actual behavior, error output with secrets removed, and the .NET version. We can confirm scope before sharing source code.
