Security research

We break things. Some of it gets published.

Tools built by people who have never run an attack tend to look like checklists. Ours comes out of finding real holes in real systems, and what we learn there goes back into BuildSecure the same week.

publicly listed

Deutsche Telekom credits us by name.

We reported an authentication bypass and PII exposure across Deutsche Telekom and its sibling organisations. Their security team lists Kahu Labs on their public acknowledgements page. You do not have to take our word for any of this.

Read it on telekom.com

A sample of what our engine has found.

The full list runs a great deal longer. What follows is a selection we can discuss publicly, anonymised, and published only once the hole was closed.

Authentication bypass, full admin takeover

We got administrator access to a client's production analytics platform by defeating the way its login tokens were signed.

Remote code execution in a public application

A client's public web application could be made to run our code. We proved it, wrote it up, and it was patched before anyone else got there.

Remote code execution through an old component

An outdated browser component inside a client environment was enough to get a foothold into their core systems.

Build server open to the internet

Source code, configuration and live API keys, readable by anyone who knew the address.

Cloud storage keys in public code

Credentials sitting in a JavaScript file the whole internet could download, with read and write access to production storage.

Debug mode left on in production

A live application handing out its database credentials, sign-in secrets and API keys through a setting somebody forgot.

Three small flaws, one real break-in

Individually all low severity. Chained together they walked through the firewall into customer data.

Weak access control on an internal platform

Staff documents that could be read, edited and exported by people who should never have reached them.

We never publish client names, affected systems, or enough detail to repeat the work. The class of issue and its impact, nothing more.

Start here

Curious what we would find in yours?

Pick a system. We run a scoped review and show you the findings with the evidence attached.

or write to hello@kahulabs.com
Request a scoped review