Skip to content
Book a call

Home / Blog

Field notes from the engagements

Blog

What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.

Engagements and Process

“We Don’t Need a Pentest. You Won’t Find Anything.”

That was the first sentence out of a client's mouth. They had tested a month earlier, with a generic vendor, because a customer required a report. Their systems…

Read it

Engagements and Process

The Previous Test Found Nothing. We Found Account Takeover.

A client came to us after working with another vendor whose report said everything was fine apart from minor findings. Data theft, identity tampering, denial of service and…

Read it

Cloud Security

Firestore White Box Security Review Checklist

Table of Contents Introduction Securing your application’s Firestore database is crucial for protecting sensitive data and maintaining user trust. Google Firestore, a scalable NoSQL cloud database, offers robust…

Read it

Engagements and Process

“Would You Like to Write a Book About That?” – How One Talk Became a Book and a Company

Two people from Syngress came up to me as I came off the Black Hat stage in 2009. Saying yes meant leaving a salaried job, with a mortgage…

Read it

Black Box Testing

Firestore Database – Black Box Security Testing Guide –  Go Beyond *.firebaseio.com/.json

Table of Contents Incentives Firestore security is an important topic for modern applications. Its wide usage and serverless architecture may cause security issues in the areas such as…

Read it

Black Box Testing

A Guide For Advanced Message Protected API Hacking Using Hackvertor and Burp (Part #2)

Table of Contents More up-to-date Hackvertor game-changer techniques, code examples, and tips for advanced penetration testing and bug bounty. Intro Hackvertor is a Burp extension that programmatically extends…

Read it

Black Box Testing

Advanced Testing Of Web Application With Custom Message Signing Using Hackvertor (Part #1)

Table of Contents Introduction Many of us have probably been faced with testing an application with custom HTTP request authentication or message signing. The requests from these applications…

Read it

Cloud Security

Firebase Applications – The Untold Attack Surface

Introduction In this blogpost, we will review some of the basic components of a Firebase application from a Security Perspective and talk about common issues that don’t get…

Read it

Mobile Security

Understanding the Android clearTextTrafficPermitted Flag

Introduction The cleartextTrafficPermitted flag is one of the options in Android’s Network Security Configuration file. The online documentation (https://developer.android.com/training/articles/security-config) explains that from Android 9 (API level 28) and higher, it will…

Read it

Brute Force

Brute Force Prevention

Following the first part of the article, which explained the brute-force attack and its different techniques, the following article will enumerate the possible mitigations that can be implemented…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue