xDeadSignalx

White hat. Your side.

I attack websites, web apps, APIs and web3 projects the way a real adversary would, then show you exactly what I found and how to close it.

White fedora
01
Results

What the work has been worth

Real numbers from client engagements. The details stay between me and the owner.

$0
saved for clients in prevented breach costs, refunds and downtime
0
threats found, reported and confirmed closed on retest
0%
of findings delivered with steps to reproduce and a fix
Example run · details redacted
02
About

I'm xDeadSignalx.

I do ethical hacking for anyone who runs something on the web: a SaaS, a store, an API, a crypto project, a landing page with a login behind it. Most of them go live without anyone trying to break in first. I try first, so the next person who tries isn't a stranger.

You get a plain report ranked by severity, with steps to reproduce and a fix for each finding, and I check again after you patch.

03
Services

What I actually test

Named by technique, not buzzword. If it's on the OWASP lists or in a real breach write-up, it's in scope.

01

Web application attacks

Cross-site scripting (stored, reflected, DOM), SQL and NoSQL injection, command injection, server-side template injection, path traversal, unsafe file uploads, insecure deserialization.

02

Auth and access control

IDOR and broken object-level authorization, privilege escalation, JWT and session flaws, OAuth and SSO misconfiguration, password reset and MFA bypass, missing rate limits on login.

03

APIs

REST and GraphQL: mass assignment, excessive data exposure, SSRF, introspection left on, endpoints missing authorization checks, abuse of batch and bulk operations.

04

Data and PII exposure

Personal data leaking through responses, public storage buckets, exposed .env and .git, secrets in client bundles, verbose errors and logs, backups left online.

05

Crypto and web3

Smart contract review (reentrancy, access control, oracle and price manipulation, unchecked external calls), dApp front-ends and wallet-connect flows, signature and approval phishing surfaces, key and RPC handling, bridge and token integrations.

06

Business logic and infrastructure

Race conditions, payment and coupon manipulation, CSRF, open redirects, clickjacking, CORS and security-header misconfiguration, subdomain takeover, outdated dependencies with known CVEs.

07

Retest and license

After fixes ship I re-run every finding. When they hold, the site gets a license: a record anyone can look up here and a badge for your footer.

04
Process

How a job runs

01

Scope

We agree on what's in bounds: domains, apps, APIs, contracts.

02

Test

I work through the target without touching real users or taking anything down.

03

Report

Each issue with severity, steps to reproduce, and how to fix it.

04

Retest

Once you've patched, I verify every fix holds.

05

License

Fixes confirmed, the site gets its license ID and badge, verifiable here.

05
Licenses

Licensed by xDeadSignalx

When a site passes retest it gets a license: a record on this site and a badge for theirs. Anyone can look up a domain here before trusting the badge.

Licensed by xDeadSignalx badge
  • Verifiable. Search any domain or license ID and see whether it's real.
  • Dated and scoped. The record says what was tested, when, and how long it's valid.
  • Earned on retest. Only issued after the fixes are confirmed. Never sold on its own.
06
Ground rules

Ethical means ethical

07
Contact

Want your site checked?

Send the link and a line about what it does. Pick whichever channel you already use.