Opera
A subdomain takeover led to control of the SIP/VoIP destination infrastructure. Telephony clients could consequently be directed to infrastructure outside the operator’s control.
Public case studyI test agreed internet-facing web applications, APIs and IT services with respect for your operations. I assess every finding personally and help your team through remediation and retesting. We agree testing windows, methods and stop procedures with your operations team.
Three examples from my published security research show the consequences of flaws in externally reachable systems.
A subdomain takeover led to control of the SIP/VoIP destination infrastructure. Telephony clients could consequently be directed to infrastructure outside the operator’s control.
Public case studyTwo RBAC bypasses allowed intended permission checks to be circumvented. The assigned role did not constrain access as intended.
Published researchCVE-2026-1190: A missing expiry check allowed delayed SAML responses to be accepted beyond the intended time window.
Official Keycloak issue#2 VDP Researcher Germany on HackerOne, Q1/2026 · VDP = Vulnerability Disclosure Program
What is affected? What could the flaw cause? Who owns the fix? The report connects evidence and priorities with practical remediation steps and retest status.
The public sample includes a PDF report, a separately downloadable findings update and an HTML reading view. All systems, data and results in it are fictional.
View sample reportFictional sample
Before starting, we record which systems may be tested, which access is available and which methods and testing windows fit your operations.
Hardware and firmware research is a separately commissioned reverse engineering engagement.
Critical infrastructure status alone does not justify daily tests. Changes, external exposure and the consequences of a vulnerability determine the cadence. Monthly or weekly testing may be more appropriate for a stable attack surface.
Industrial controls, OT and safety-critical process systems are outside this offering. Responsibilities, testing windows, excluded methods and stop procedures are agreed with operations. A pentest report is not a compliance certification.
Record systems, test access, methods and testing windows in writing.
I use my own testing setup and personally assess every finding for reproducibility, relevance and impact.
Agree priorities and owners, hand findings to your team and work through practical remediation steps.
Retest remediated findings within the agreed scope and update their status. Included during the active contract term.
Monthly for stable applications, weekly for regular releases, daily when frequent changes or critical exposure justify it. We agree scope and cadence before starting.
Regular price: from €1,999
Promotional price: from €1,399
per month, excl. VAT
Monthly testing and a comprehensive findings update.
For stable applications with few changes to the external attack surface.
Regular price: from €5,999
Promotional price: from €4,199
per month, excl. VAT
Weekly testing and an updated findings report.
For product teams shipping regular releases, new APIs and ongoing changes to internet-facing systems.
Regular price: from €9,999
Promotional price: from €6,999
per month, excl. VAT
Daily testing and an updated findings report.
For high-output startups, enterprises and critical infrastructure with frequent changes or critical exposure. Otherwise, monthly or weekly is usually enough.
Personal assessment, a prioritized report and agreed ticket handover. Time with operations, remediation support and knowledge transfer to help your teams improve security workflows across the organization.
All packages include retesting of remediated findings within the agreed scope and during the active contract term.
All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price. Systems, methods, testing windows and communication channels are defined before work starts. The cadence describes the agreed testing and report updates.
I handle your engagement and take personal responsibility for the technical assessment. We work through root causes, mitigations and testing criteria with operations and development using concrete findings.
We hand findings to Jira, Linear or GitHub using an agreed format or access you provide. We assign owners and keep remediation and retest status traceable.
Available capacity and parallel engagements, arrangements for holidays or illness, and the notification channel and response time for critical findings are agreed in your quote before work starts.
You receive the testing service, assessed findings and collaboration with me. Customers receive no access to the tools or models used.
Technical background in the case studyRegular monthly fees start from €1,999 for monthly testing, from €5,999 for weekly testing and from €9,999 for daily testing, excluding VAT. All prices are starting prices. The final monthly fee depends on the number and extent of the agreed scopes and may be higher. Your quote confirms the binding price. Book by 30 September 2026. Save 30% for your contract term. For pentest packages booked on or before 30 September 2026 (Europe/Berlin). The saving applies for the entire agreed contract term. We agree the project start separately. Terms are confirmed in your quote.
The authorized websites, APIs and internet-facing services, their complexity, available test access and operational constraints determine scope. The proposal records the systems and coverage. Custom reverse engineering is quoted separately based on the device, complexity and required test hardware.
A pentest is a snapshot of the agreed testing scope. New releases, library updates, additional API endpoints and configuration changes keep changing your external attack surface. Later changes and newly disclosed vulnerabilities are not automatically covered by the existing report. Recurring tests shorten the time that changes remain untested. Findings are assessed and remediated, then fixes are retested. One-off tests remain useful for a baseline assessment or before a launch. For systems under active development, testing frequency should match the pace of change and the risk.
For stable applications with limited changes, monthly testing is often a practical start. Weekly testing suits regular releases. We recommend daily testing for high code output, multiple teams or critical external exposure, rather than for every business by default.
We agree the scope together. I review every finding for reproducibility and relevance, then help your team prioritize, remediate and retest. You receive professionally assessed results and work directly with the specialist responsible for the engagement.
All packages include retesting of remediated findings within the agreed scope and during the active contract term.
Yes. We agree a handoff to Jira, Linear or GitHub using a suitable format or access you provide. Each finding includes priority, evidence, remediation guidance and retest status. We agree ownership together.
I handle your engagement and take personal responsibility for the technical assessment. Available capacity and parallel engagements, arrangements for holidays or illness, and the notification channel and response time for critical findings are agreed in your quote before work starts.
Reverse engineering for routers, appliances and other devices. Separately commissioned, with a dedicated test setup and pricing on request.
Bring your web applications, APIs and reachable services. Together we agree the scope, testing cadence and the right price.