Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

Sessions Explained: How Websites Remember Who You Are

Sessions Explained: How Websites Remember Who You Are

Blog Summary

HTTP forgets you after every request, yet you stay logged in for hours. Here's what really happens: the session ID cookie, server-side storage, expiry, session fixation, and choosing a Laravel session driver.

Read more
  • 57
  • 79
  • 7

Passkeys Explained: Is This Finally the End of Passwords?

Passkeys Explained: Is This Finally the End of Passwords?

Blog Summary

Passkeys can't be phished, reused or leaked from your database, and users log in with a fingerprint. So why do most sites still ask for a password? How passkeys work, what WebAuthn looks like in code, and the parts nobody mentions.

Read more
  • 76
  • 106
  • 8

File Upload Security Mistakes in PHP Apps (and the Safe Laravel Way)

File Upload Security Mistakes in PHP Apps (and the Safe Laravel Way)

Blog Summary

An upload form lets a stranger put a file on your server. Five classic PHP upload mistakes, from trusting the MIME type to storing files in the web root, why each one is dangerous, and the safe Laravel approach.

Read more
  • 140
  • 42
  • 17

Hardening a Linux Server for a Laravel App: A Practical Checklist

Hardening a Linux Server for a Laravel App: A Practical Checklist

Blog Summary

Bots start knocking on a new server within the hour. A practical hardening checklist for Laravel on Ubuntu: automatic updates, SSH keys only, a deny-by-default firewall, fail2ban, least-privilege file permissions, HTTPS and tested backups.

Read more
  • 138
  • 133
  • 21

Two-Factor Authentication: How Those Six-Digit TOTP Codes Actually Work

Two-Factor Authentication: How Those Six-Digit TOTP Codes Actually Work

Blog Summary

Your authenticator app and the server agree on the same six digits with no network at all. Here's the shared secret, the 30-second clock and the HMAC behind it, plus where 2FA is strong and where it isn't.

Read more
  • 120
  • 12
  • 13

Laravel Validation Rules You're Probably Not Using (But Should Be)

Laravel Validation Rules You're Probably Not Using (But Should Be)

Blog Summary

Most Laravel apps validate with required, string and max, then hand-code the rest in controllers. Unique-ignore, scoped exists, sometimes, bail, prohibited_if, Password and enum rules do it better. Each one with the problem it solves.

Read more
  • 143
  • 98
  • 19

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close