Case: Blocking REST User Enumeration Stopped Targeted Brute-Force Attackers were pulling usernames from /wp-json/wp/v2/users, then brute-forcing those exact accounts. 12 valid usernames were exposed. …
Case: wp-config Hardening Blocked a Live Disclosure Attempt During an audit, wp-config.php was world-readable and the DB user had full GRANT ALL. Hardening SOP: — Step 1: chmod 600 wp-config.php, owne…
Case: One Rate-Limit Rule Absorbed a 220k-Request Burst A Black Friday landing page got hit with a layer-7 burst: 220,000 requests in 11 minutes from 1,400 IPs, all hammering /?s= search. WAF SOP we k…
Case: Five Headers Moved Observatory From F to A+ Client site scored F on Mozilla Observatory (15/100). No security headers present. Header SOP, added at the edge: — Step 1: Strict-Transport-Security:…
Case: Cutting 22 Admins to 4 Shrank the Blast Radius A media site had 22 accounts with administrator role. Nobody could say why. Two belonged to ex-contractors still active. Least-privilege SOP: — Ste…
Case: One chmod Sweep Found 1,847 World-Writable Files Inherited a hosting account after a malware cleanup. A previous "fix" had set huge swaths of files to 0777. Audit SOP: — Step 1: Inventory the da…