An OSWE-style white-box web review: read the source, identify the sink, reason the exploitation logic, verify, and remediate
A white-box secure code review of Larchmont Portal, a fictional partner-facing web application. Read the source, identify the vulnerable sinks, reason through the conceptual exploitation path, verify impact and scope, then write the remediation report. No exploit code involved — this is source-to-sink reasoning only.