PENTEST | Геннадий Михалков

В этой теме можно использовать автоматический гарант!

Геннадий Михалков

RAID-массив
Пользователь
Регистрация
16.05.2022
Сообщения
57
Реакции
30
Депозит
6 Ł
Контакты
t.me/genkapentest
IMAGE-2025-12-01-20-12-59.jpg


About Me :smile10:
Professional specialist in application and infrastructure security assessment. I work in accordance with international security standards, performing the full cycle of testing, vulnerability identification, and preparation of detailed reports with remediation guidelines. I have experience with web applications, mobile applications, APIs, network infrastructure, and cloud platforms.

Services. :smile50:

Web Application Penetration Testing :zns6:
— business logic assessment
— authentication and authorization testing
— OWASP Top 10 vulnerability analysis
— API, GraphQL, and WebSocket testing
— file upload and validation mechanism testing
— server configuration and middleware assessment
— final report with evidence and recommendations

Mobile Application Penetration Testing (Android, iOS) 👾
— static analysis of APK and IPA
— dynamic testing in a sandbox environment
— analysis of data storage and file system interactions
— backend API communication testing
— verification of encryption mechanisms and SDK security
— compliance with OWASP MASVS/MSTG

API Security Assessment ⌨️
— testing REST, SOAP, and GraphQL APIs
— assessment of authorization implementations (OAuth 2.0, JWT)
— evaluation of brute force protection and rate limiting
— identification of logical flaws and incorrect interaction scenarios
— analysis of microservice communications

Network Infrastructure Testing
— external and internal penetration testing
— perimeter security assessment
— evaluation of VPN, WAF, IDS, and IPS
— configuration audit of network devices
— protocol analysis and attack surface identification

Security Architecture Review
— assessment of application and infrastructure architecture
— early identification of potential weaknesses
— analysis of secure authentication schemes
— audit of DevOps and CI/CD practices

Source Code Review
— security-focused code audit for major programming languages
— analysis of critical components: authentication, encryption, file handling, session management
— remediation recommendations

Reverse Engineering
— binary analysis
— evaluation of logic integrity and application protection
— review of packing, obfuscation, and anti-reversing techniques

Red Teaming and Social Engineering (with official authorization)
— simulation of real-world attack scenarios
— assessment of phishing resilience and social engineering exposure
— evaluation of human factor risks
— strict adherence to legal requirements

Cloud Security Assessment
— audit of AWS, GCP, and Azure
— analysis of IAM configurations, network policies, roles, and permissions
— evaluation of secrets management, logging, container configurations, and orchestration setups

Post-Audit Support
— developer consulting
— verification of fixes
— architecture improvement
— regular security reassessment

Deliverables for the Client
— complete technical report
— executive summary for management
— vulnerability evidence
— risk prioritization
— remediation guidelines
— revalidation after fixes if required
 
Dear colleagues, due to a large influx of orders and my primary work, I want to inform and emphasize: I only do ethical pentest. I can analyze patches or CVE, scan, and find all subdomains. The work is completely manual. I work starting from the amount of my deposit on the forum; I do not work with amounts of $400, $300, $200, or $100.

I only work with large orders and solvent clients - thank you.
 
Web Application Penetration Testing — 750 - 3000 USD
Mobile Application Penetration Testing — 1000 - 3500 USD
API Security Assessment — 600 - 2500 USD
Network Infrastructure Testing — 1250 - 6000 USD
Security Architecture Review — 1000 - 4000 USD
Source Code Review — 7.5 - 20 USD за 100 строк кода
Reverse Engineering — 750 - 3500 USD
Red Teaming and Social Engineering — 4000 - 15000 USD
Cloud Security Assessment — 1250 - 4500 USD
Post-Audit Support — 50 - 120 USD в час

GARANT +
 
Dear colleagues, due to a large influx of orders and my primary work, I want to inform and emphasize: I only do ethical pentest. I can analyze patches or CVE, scan, and find all subdomains. The work is completely manual. I work starting from the amount of my deposit on the forum; I do not work with amounts of $400, $300, $200, or $100.

I only work with large orders and solvent clients - thank you.
ur deposit is 0.176 Ł = 13$

Source Code Review — 7.5 - 20 USD за 100 строк кода --- так уже бери по 1$/1line
 
Всем доброго - субботнего утра. Уважаемые форумчане, хочу вас уведомить: Я не дамплю и не взламываю чьи либо сервисы, веб сайты и приложения. Мой сервис заключается в анализе и выявление слабых уязвимых мест, с последующей выдачей хорошего, понятного, профессионального отчета. Мне абсолютно неинтересно для каких целей вы используете мои анализы и аналитику в последующем и все риски и ответственность вы берете исключительно на себя. Я не работаю по странам СНГ без договоров о потребительском заказе в области - ВЕБ ПЕНТЕСТА.

Web Application Penetration Testing — 750 - 3000 USD
Mobile Application Penetration Testing — 1000 - 3500 USD
API Security Assessment — 600 - 2500 USD
Network Infrastructure Testing — 1250 - 6000 USD
Security Architecture Review — 1000 - 4000 USD
Source Code Review — 7.5 - 20 USD за 100 строк кода
Reverse Engineering — 750 - 3500 USD
Red Teaming and Social Engineering — 4000 - 15000 USD
Cloud Security Assessment — 1250 - 4500 USD
Post-Audit Support — 50 - 120 USD в час

Так же хочу сообщить: СКУПАЮ 0day на Android - root (Гарант+)

СКИДКА 25% ДЛЯ НОВЫХ КЛИЕНТОВ
 


Напишите ответ...
Верх