Real numbers from client engagements. The details stay between me and the owner.
I do ethical hacking for anyone who runs something on the web: a SaaS, a store, an API, a crypto project, a landing page with a login behind it. Most of them go live without anyone trying to break in first. I try first, so the next person who tries isn't a stranger.
You get a plain report ranked by severity, with steps to reproduce and a fix for each finding, and I check again after you patch.
Named by technique, not buzzword. If it's on the OWASP lists or in a real breach write-up, it's in scope.
Cross-site scripting (stored, reflected, DOM), SQL and NoSQL injection, command injection, server-side template injection, path traversal, unsafe file uploads, insecure deserialization.
IDOR and broken object-level authorization, privilege escalation, JWT and session flaws, OAuth and SSO misconfiguration, password reset and MFA bypass, missing rate limits on login.
REST and GraphQL: mass assignment, excessive data exposure, SSRF, introspection left on, endpoints missing authorization checks, abuse of batch and bulk operations.
Personal data leaking through responses, public storage buckets, exposed .env and .git, secrets in client bundles, verbose errors and logs, backups left online.
Smart contract review (reentrancy, access control, oracle and price manipulation, unchecked external calls), dApp front-ends and wallet-connect flows, signature and approval phishing surfaces, key and RPC handling, bridge and token integrations.
Race conditions, payment and coupon manipulation, CSRF, open redirects, clickjacking, CORS and security-header misconfiguration, subdomain takeover, outdated dependencies with known CVEs.
After fixes ship I re-run every finding. When they hold, the site gets a license: a record anyone can look up here and a badge for your footer.
We agree on what's in bounds: domains, apps, APIs, contracts.
I work through the target without touching real users or taking anything down.
Each issue with severity, steps to reproduce, and how to fix it.
Once you've patched, I verify every fix holds.
Fixes confirmed, the site gets its license ID and badge, verifiable here.
When a site passes retest it gets a license: a record on this site and a badge for theirs. Anyone can look up a domain here before trusting the badge.
Send the link and a line about what it does. Pick whichever channel you already use.