I will map your external attack surface and find what you forgot you exposed

Spain

I speak Russian, English, Spanish

Manual pentesting for web apps, APIs and AI generated code

Scanners cannot tell you whether a customer can refund their own order, read another user's data, or replay a payment webhook. I test that by hand. Fifteen years of building the systems I now break: ...
About this Gig

Guarantee: every finding comes with the exact request that reproduces it. If you cannot reproduce one on your own system, I remove it and refund that part.


Most breaches start somewhere nobody meant to publish. A forgotten staging host. An old subdomain still pointing at a dead service. A storage bucket left open. A key committed to a public repository.


I look at your company the way an attacker does before touching anything: from the outside, without credentials, without sending anything intrusive.


What you get: every asset I can attribute to you, what is exposed on it, which findings are actually reachable, and what to shut down first.


Passive by default. Nothing intrusive is sent, and nothing is tested actively without your written authorisation.


Nineteen years on Linux and networks before moving into security research: DNS and mail, VPNs, dual-stack IPv4 and IPv6, AWS networking and IAM.


Everything runs in writing. No calls needed.

Testing application:

Website

Development technology:

HTML & CSS

JavaScript

Node.js

PHP

Python

Device:

PC

Mac

Linux

iPhone

Android mobile phone

My Portfolio