Hack Glasgow 2026

Ehren Osborne

Hi there! I am Ehren, a CHECK team member working at KPMG in Leeds (though I am from South Wales!).
I am a huge web application enthusiast and spend alot of my free time researching and studying obscure application vulnerabilties, recently delving into creating labs to demonstrate some of them!
In my spare time I boulder and play competitive counter strike, feel free to chat to me about any of the above!


Session

08-15
13:30
25min
Please, oh please, stick to the RFCs
Ehren Osborne

"Please, oh please, stick to the RFCs" is both my technical recommendation and a plea for my sanity while testing certain web applications. My talk will firstly explore some pre-requisites, such as; My path to being a web application tester, what an RFC is and what circumstances made me realise that this needed to be heard.

RFCs are written to guide the usage and application of protocols, with the HTTP-related RFCs being the main focus. I will highlight parts from the RFC that directly relate to vulnerability classes application frequently see and discuss how just like a software update, RFCs that are obsoleted, are done so for a good reason.

While I’m sure there will be at least one person in Leeds (most likely a colleague or friend I’ve convinced to attend), who would enjoy a pure RFC discussion, I prefer my talks to be practical. They’re built around stories and scenarios that shaped my mindset, including the path and people who influenced me along the way. Importantly, I will share real-life examples from tests I’ve conducted to back up my points and to show both how interesting the vulnerabilities caused by ignoring RFCs can be, and how frustrating they are to test in practice.

For the newer generation (either getting into or starting) of testers, you will hopefully learn a bit about RFCs, could application practice and hear some cool stories which may inspire a couple more web application testers!

For the current testers, particuarly the app ones, you will share my pain of non-sensical application behaviour impacting testing, see a couple more cool war stories and might learn just a little bit more about some hidden details in the RFC!

So whether you are wanting to learn more about RFCs, or simply hear some fun stories, feel free to come along!

Stage 2