On GitHub
Pentest & Code Review
Penetration Testing and Security Assessment Services
We find security vulnerabilities in web applications, web services, APIs, AWS, Azure & GCP infrastructure, serverless applications, mobile applications built for Android, iOS and software written for Internet of things (IoT). Our comprehensive security assessments include threat modelling, architectural reviews, pentesting and source code review.
- WEB
- Web service/app
- Scope: Web Services, APIs & Servers
- Duration: 2-7 weeks
- Standards: OWASP Web, SANS 25
- Report: PDF Report
- Retest: Included
- MOBILE
- Android/iOS app
- Scope: Android, iOS & Web APIs
- Duration: 3-7 weeks
- Standards: OWASP Mobile, MSTG
- Report: PDF Report
- Retest: Included
- CLOUD
- Cloud infrastructure
- Scope: AWS, Google Cloud, & Azure
- Duration: 3-7 weeks
- Standards: OWASP, CIS Benchmark
- Report: PDF Report
- Retest: Included
Services we offer
- Web Application Pentest & Security Assessment
- AWS, Azure and Google Cloud Security Assessment
- Compute and Serverless Security
- Server, Database and Application Security
- Wordpress/Drupal/Joomla Security and Hardening
- Mobile Application Pentest & Security Assessment
- Infrastructure and Application Stack Security Assessment
- Secure Code Review & Threat modelling
- Security Algorithm design and implementation
- Evaluation of custom Security implementations & protocols
- Application Security Automation, Scripting
- Security Engineering & Security Tool Development
- Application Security Consultancy & Startup Advisory
Security Training
Deep technical application security trainings.
We provide application security trainings and certification via self paced online courses as well as hands on live trainings at Security conferences. Our trainings cover web application security, mobile application security, pentesting modern technology stack, and windows exploit development. For more information, visit our security education portal
Security Engineering
We love security automation and develops security tools that work.
Security Engineering is our speciality. We build open source security tools in Python, Golang, Lua, Node.js, .NET, JavaScript and Java.
On GitHub
nodejsscan Static Code Scanner
On GitHub
OWASP Xenotix XSS Exploit Framework
On GitHub
Garfield Distributed System Scanner
On GitHub
CMSScan, CMS Security Management
On GitHub
njsscan, SAST for node.js
We help companies implement fundamental blocks of a successful Application Security program. Reach out if you would like us to help you integrate appsec tooling in your CI/CD pipeline or has custom security software and automation requirements.
Support Services
Mobile Security Framework Support Packages.
All rates are in USD inclusive of taxes, but excluding any withholding taxes and transaction fees.- PROFESSIONAL
- $ 2999.99 / year
- Live Support & Troubleshooting
- Priority Support via Email or Slack
- Access to MobSF e-Learning Course (5 accounts)
- 1 Minor Feature Request
- Priority Bug Fixes
- ENTERPRISE
- $ 6999.99 / year
- Live Support & Troubleshooting
- Priority Support via Email or Slack
- Access to MobSF e-Learning Course (15 accounts)
- 2 Major Feature Requests
- Priority Bug Fixes
- TRAINING
- $ 10999.99 / year
- Onsite*/Online Live MobSF Training for your Developers
- CTF challenges
- Assistance in setting up MobSF in your CI/CD
- Access to MobSF e-Learning Course (50 accounts)
- Expert Email Consultation
Security Research
Latest advisories and research from OpenSecurity.
- Detecting zero days in software supply chain with static and dynamic analysis
- Stealing card details from contactless cards in seconds
- Exploiting insecure file extraction in Python for code execution
- Exploiting deserialization bugs in Node.js modules for Remote Code Execution
- Server Side Template Injection in Tornado
- Instamojo Woocommerce Plugin XSS
- OS X Mavericks 10.9.5 - out of bound read/write in memmove()
- AppLock MITM Password Reset Vulnerability
- Reversing DexGuard's String Encryption
- Bypassing Content Security Policy with a JS/GIF Polyglot
- Bypassing PIN in Whisper Android Application
- Tizen 2.2.1 WebKit Address Spoofing
- MTS MBlaze Ultra Wi-Fi / ZTE AC3633 Multiple Vulnerabilities