IT-Security Made In GerMany
Continuous Penetration Testing
Small- and mid-sized organizations often lack the personnel or knowledge to cover their entire digital attack surface. We’re here for you to fill this gap!
Integrate security into your organization
All you have to do is give us your asset information – including domain names, IP addresses and mobile apps and we’ll do the rest.
Kick-Off
We’ll talk about your attack surface and you’ll give us permission to monitor it.
Coverage
We’ll cover all your company’s assets. 24/7.
The fun part.
Once we’ve got all your digital assets, we start continuously monitoring your assets for security vulnerabilities. All discovered vulnerabilities are evaluated by our certified security analysts to save you more time focusing on your business. You will never get an unchecked report!
Fast & Easy for you
We’ll get in touch proactively if there is a vulnerability found; even with affected vendors!
Reporting
You’ll get a report which summarizes the identified vulnerabilities and all necessary steps to remediate it.
Additional Benefits!
We understand that the security of your data is important, which is why we store every single byte in German datacenters.
Data Stored in Germany
Elevating our commitment to data security and privacy, all your data is exclusively stored in a datacenter in Germany. We understand the paramount importance of aligning with stringent GDPR regulations, and by choosing our services, you gain the added assurance that your sensitive information is stored in a country renowned for its robust data protection framework
What we have to offer
Affordable for any budget.
Attack Surface Management
We continuously monitor your attack surface and notify you of any vulnerabilities discovered.
Penetration Tests
We also perform classic penetration tests against almost any of your assets: web apps and apis, IoT devices or thick client apps.
Source Code Reviews
We also perform source code reviews of applications written in Java, .NET, PHP, Python or JavaScript.
Bug Bounty and VDP Services
Do you want to run your own bug bounty or vulnerability disclosure program? With more than 10 years experience, we have you covered!
Custom IT Security Consulation
We can assist you in security engineering related topics such as how to securely build new apps or APIs.
Latest News
Discover our newest blog posts.
WordPress GiveWP POP to RCE (CVE-2024-5932)
A few days ago, Wordfence published a blog post about a PHP Object Injection vulnerability affecting the popular WordPress Plugin GiveWP in all versions <= 3.14.1. Since the blog post contains only information about (a part) of the POP chain used, I decided to take a look and build a fully functional Remote Code Execution exploit. This post describes how I approached the process, identifying the missing parts and building the entire POP chain.
Patch Diffing CVE-2023-28121 to Compromise a WooCommerce
Back in March 2023, I noticed an interesting security advisory that was published by Wordfence about a critical "Authentication Bypass and Privilege Escalation" (aka CVE-2023-28121) affecting the "WooCommerce Payments" plugin which has more than 600.000 active...
SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897)
While my last finding affecting SecurePoint's UTM was quite interesting already, I was hit by a really hard OpenSSL Heartbleed flashback with this one. The following exploit works against both the admin portal on port 11115 as well as the user portal on port 443....