Bitcoin Forum
June 19, 2024, 09:59:21 PM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Afraid of getting hacked? Hire an (ethical) hacker today!  (Read 1608 times)
agileinfosec (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 10, 2014, 05:25:16 PM
 #1

Hi,

Do you run a website that deals with bitcoins or a large amount of money and want your code reviewed by a security specialist?
I'm an ethical hacker that specialises in web application security.

I have found security flaws in many websites, CMS, etc, written in ASP, .NET, PHP, JavaEE/Spring/etc, pure JS, whatever; and I've contracted for major oil companies, investment banks, large retailers, online gaming companies, etc.

I provide the following services (separate or in tandem):
- Penetration testing: I will try to hack your website from the outside like a hacker would, using manual and automated tools
- Source code review: I will review your code for security vulnerabilities, logic flaws, etc and even provide patches if you want (and pay for it)

My prices are much cheaper than hiring a security consultancy, and the scope of the work and cost will be agreed beforehand to avoid surprises.

You can see my LinkedIn at www.agileinfosec.co.uk and all the issues I've found in application software in http://osvdb.org/creditees/10950-pedro-ribeiro.

Contact me via PM or email pedrib_at_gmail.com if you are interested.
blueangel01
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250

Hello! Send me a message.


View Profile
March 10, 2014, 05:29:32 PM
 #2

Would you be interested if i pay you a shares of the company instead?

Msg me if you want me to put anything here.
agileinfosec (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 10, 2014, 05:34:13 PM
 #3

Hi blueangel01, thanks for the enquiry, but no.
Payment would have to be done in bitcoin or "normal" bank transfer to the UK.

Don't be afraid to ask for a quote, it might be cheaper than you expect.
E.exchanger
Hero Member
*****
Offline Offline

Activity: 714
Merit: 500


NEED CRYPTO CODER? COIN DEVELOPER? PM US FOR HELP!


View Profile
March 10, 2014, 08:33:15 PM
 #4

I've contracted for major oil companies, investment banks, large retailers, online gaming companies, etc.


Firstly why would such huge firms like oil companies, bank etc hire a freelancer Huh They have a huge hierarchy to cover after all they only go for registered professional companies. Anyways please mention what kind of prices are you taking about give a range like 0.1 to 3BTC depending on the website.also if you found any vulnerability in my site would it cost me more to fix it or its been included in the service fees Huh   
agileinfosec (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
March 11, 2014, 09:34:27 AM
 #5

Anyways please mention what kind of prices are you taking about give a range like 0.1 to 3BTC depending on the website.also if you found any vulnerability in my site would it cost me more to fix it or its been included in the service fees Huh 

OK, here are the services I provide in more detail:
1) Automated black box penetration test: 0.5 bitcoin (fixed price)
2) Manual black box penetration test (no source code review): 0.5 bitcoins per day
3) Manual white box penetration test (includes source code review): 1 bitcoin per day

The cost for the automated test is a fixed price. The manual tests will take anywhere from 2 to 15 days depending on the complexity of your website - how many dynamic pages, etc. 1) will give you a reasonable assurance that script kiddies and lame hackers cannot attack you, 2) will give you an assurance your site is protected against skilled hackers, while 3) will give you a very good assurance that you are protected against most attackers.

For all services I will give you a report detailing what's wrong, what is the risk, how I found it and how to fix it.
For services 1) and 2), because I don't have access to the source code the report will contain generic recommendations (filter this input variable, etc).
For service 3), I can pinpoint the line number and tell you how to fix it. You can give this report to a developer and I will answer any questions he/she has. If you would like me to fix the issue, we can agree on a price per issue. If it's something simple like cross site scripting (about 50% of the time) the fix will be free.

As a comparison, prices in the UK for these services range from £1000 to £1500 a day, while in the US from $1200 to $2000 a day.

Firstly why would such huge firms like oil companies, bank etc hire a freelancer Huh They have a huge hierarchy to cover after all they only go for registered professional companies.

I am the founder and sole owner of a registered professional company - look for Agile Information Security Limited UK in Google and you can find my public records such as registered office, company accounts, etc. I can provide more proof including the certificate of corporation and tax registration letter, etc if you require. Website is coming up soon.

There is a severe shortage of information security specialists in the United Kingdom (and globally), which is driving prices and salaries up. Many people are (like me) going solo as this gives you more flexibility and better pay.
You can find more information on:
http://www.adecco.co.uk/employers/employer-guides/value-of-recruiting-contractors.aspx
http://www.zdnet.com/uk/skills-shortage-threatening-uk-cybersecurity-could-last-for-20-years-7000011169/
http://blogs.cisco.com/security/bridging-the-looming-global-it-security-professional-shortage/
http://www.computerweekly.com/news/2240178584/RSA-2013-Cyber-security-skills-shortage-needs-urgent-attention-says-DoHS
chip99
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
March 11, 2014, 05:58:34 PM
 #6

humans dont have a ethic...

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!