About GK Data LLC

The person you speak with does the work.

Garrett Kohlrusch handles website repair and monthly care from Blaine, Minnesota, plus authorized vulnerability research and application security review, from the first question through the written result.

GK Data is based in Blaine, Minnesota. Work is local and remote: website repair and monthly care when a site needs an operator, plus authorized vulnerability research and application security review.

Authorized research and website care.

Clients work directly with the person doing the research, repair, and review, so the written scope, observed behavior, and care plan stay tied to the system under review.

01

Offensive security

Authorized bug hunting and application, mobile, network, and cloud review focused on access control, authentication, exposed client behavior, and attack paths that can be confirmed.

02

Reporting standard

Written authorization, affected roles or assets, reproduction context, demonstrated impact, remediation direction, and stated limitations.

03

Website repair and care

WordPress stabilization, domain and hosting ownership cleanup, documented accounts, monthly maintenance subscriptions, and practical handoff for small businesses in Blaine, MN and remotely.

Current credentials

01CompTIA Security+
02CompTIA Network+
03IBM Cybersecurity Analyst Specialization
04ITIL 4 Foundation

Public work

Research where disclosure is permitted.

Company and program names appear only where disclosure is public or otherwise permitted. Private evidence and callback details stay out.

Responsible disclosureGK / SM

NASA GLOBE Observer Stored XSS Case Study

  1. 01 / EntryPublic-facing route
  2. 02 / TrustIdentity and authorization
  3. 03 / ServiceAffected operation
Responsible disclosure

NASA GLOBE Observer Stored XSS Case Study

How a mobile observation comment became stored XSS on a public NASA GLOBE web page, with verified impact, root cause, and remediation.

Read the work
Research challengeGK / SS

Intigriti 0526: Unintended Stored XSS Bypass

  1. 01 / SourceInput enters the system
  2. 02 / BoundaryControls and assumptions
  3. 03 / SinkSensitive action or output
Research challenge

Intigriti 0526: Unintended Stored XSS Bypass

An unintended stored XSS path in Intigriti Challenge 0526 involving unsafe innerHTML, observed SCA Shield bypass behavior, and sink-side remediation.

Read the work
Case studyGK / EC

Blind Stored XSS Through a Text File Upload

  1. 01 / ObserveBehavior worth testing
  2. 02 / ReproduceConditions confirmed
  3. 03 / ReportImpact and next action
Case study

Blind Stored XSS Through a Text File Upload

How an accepted text file rendered as HTML became blind stored XSS inside an internal review workflow.

Read the work

Direct project inquiry

Need an application review or help getting a website back in order?

Application security

Send the application or website, the problem you are trying to solve, and any timing constraints. You will get a direct response about fit and next steps.