↑ ↑ ↓ ↓ B A psst: try the Konami code.

BASTI.NET

OFFENSIVE SECURITY // RUBY ON RAILS

$ whoami

Hi, I'm Basti. I'm learning to break software — and to build it. Padawan, not master: still in training, but the research is already real. My days go into the weeds of penetration testing and red teaming — infrastructure, web apps, and the strange new attack surface of AI & LLMs: all the places where things quietly go wrong. That research led somewhere: I'm now a member of the Omarchy Security Team.

On the other side of the keyboard I write Ruby and build with Ruby on Rails — deliberately, by hand. I made a conscious decision to master the language and the framework from the ground up before letting AI anywhere near my codebase. Knowing how something is built is the first step to knowing how it breaks.

# learning both: attacker mindset × builder's craft — that's the whole site.

$ cat ./research

$ ls ./focus

offensive_security/

Training an attacker's eye across the stack — penetration testing and red teaming, from web apps to AI & LLMs: broken auth, injections, logic flaws, prompt attacks. Still learning, already finding — responsible disclosure, always.

pentest red team ai/llm

ruby_on_rails/

Building web applications the Rails way — convention over configuration, majestic monoliths, boring tech that ships. Learning it by hand, line by line, no autopilot.

ruby rails hotwire

building_in_public/

The whole journey is public: what I learn, what I break, what I build. Notes, videos and the occasional detour — shipped as it happens, warts included.

youtube x notes

$ cat credentials.txt

$ ./contact.sh

Found a bug in my site? Even better — tell me how you found it.

# Omarchy security matters go to basti@omarchy.org — please use only that address for anything Omarchy.