Application logic
Unexpected state changes, broken workflows, and the gap between intended and actual behavior.
Independent security research
Michael Blake is a security researcher and bug bounty hunter exploring how modern web systems break—and helping teams fix them responsibly.
guest@recon.zip ~ % whoami
Michael Blake
security researcher / bug bounty hunter
status: looking closer
guest@recon.zip ~ %
I examine products from the outside in—following assumptions, edge cases, and unexpected interactions until the real attack surface comes into view.
The goal is straightforward: turn interesting behavior into clear, reproducible findings that help make systems safer.
Web applications are systems of trust. I look for the places where that trust gets blurry.
Unexpected state changes, broken workflows, and the gap between intended and actual behavior.
Authorization assumptions, identity transitions, and data crossing places it should not.
Quiet endpoints, overlooked integrations, and small details with outsized security impact.
A disciplined loop
Understand the product, its boundaries, and what it assumes to be true.
Change context, sequence, identity, and input. Follow anything that behaves differently.
Reduce the behavior to a safe, repeatable path with clear impact and evidence.
Report with precision, collaborate on remediation, and leave the system stronger.
recon.zip / end of line