Profile    Mohammed Shiroz Status   Loading  
Logo
Share This

My security
blog and Updates

It's my personal blog and my post about what was my interested in. Not regularly. If you have any questions any discussion, I'm happy you get in touch with me, and try to answer as many as possible!

Blog
Let's See
Back to blog
Filter by:
Tags
//Article

Seven AWS Mistakes Small Teams Make (and the Afternoon Fix for Each)

Seven AWS Mistakes Small Teams Make (and the Afternoon Fix for Each)

Blog Summary

Small teams don't get hacked or surprised by the bill through exotic attacks. It's root logins, public buckets, open SSH ports and backups nobody has restored. Seven common AWS mistakes and a quick fix for each.

Read more
  • 118
  • 45
  • 24

Webhooks: How They Work and How to Make Them Reliable

Webhooks: How They Work and How to Make Them Reliable

Blog Summary

A webhook endpoint takes ten minutes to write and months to get right. How webhooks work, and five rules for reliable ones: HMAC signatures, fast responses, duplicates, out-of-order events and visible failures.

Read more
  • 70
  • 38
  • 14

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

OAuth 2.0 Explained Without the Jargon: The Valet Key Guide

Blog Summary

OAuth is a valet key for your data: it lets an app park the car without reading your mail. The authorization code flow with PKCE explained step by step, plus scopes, tokens and OAuth vs OpenID Connect.

Read more
  • 46
  • 110
  • 13

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Securing a Laravel App: A Practical 12-Point Checklist Before You Go Live

Blog Summary

Laravel ships with strong security defaults, so apps get breached in boring ways: a debug flag, a mass-assignment slip, a missing ownership check. Here is the 12-point checklist I run before going live.

Read more
  • 149
  • 91
  • 20

CORS Explained: Why the Browser Blocks Your API Call (and Postman Doesn't)

CORS Explained: Why the Browser Blocks Your API Call (and Postman Doesn't)

Blog Summary

The request works in Postman, works with curl, and fails in the browser with a scary red error. CORS isn't your server refusing the call. Here's what the browser is really doing, and how to fix it properly in Laravel.

Read more
  • 144
  • 29
  • 23

Rate Limiting Your API: The Algorithms and a Laravel Example

Rate Limiting Your API: The Algorithms and a Laravel Example

Blog Summary

One script hammering your login endpoint can slow the app for everyone. Here's how fixed window, sliding window and token bucket limiting really differ, and how to set up sensible per-user limits in Laravel.

Read more
  • 99
  • 16
  • 11

01. About Shiroz

Mohammed Shiroz

Hi, I'm Mohammed Shiroz, a software engineer and AI enthusiast from Sri Lanka who turns ideas into intelligent, real-world solutions. With over 9 years of hands-on experience, I currently lead real estate ERP development at Kate Group, a...

03.My Projects

04. Categories

Ready To Start Your Project ?

Get in Touch
Close