|
August 19, 2014, 04:35:09 PM |
|
Hello,
We are offering our professional penetration testing services. This is your chance to eliminate your company/site as the next: Mintpal, Mtgox, Bitcoinica, Bter, BTC-e, Poloniex, etc. (The list goes on and on, sadly.)
Everyone on the team (excluding the Jr. slaves^H^H^H^H^H^Hmembers) have been testing for 5+ years.
We can offer the following:
1. Web application testing - Framework testing - Remote application testing - Injection testing - Remote Command Exection - Information Disclosure - Session fixation vulnerabilities - Lots more. - Code Audit* (PHP, Perl, Ruby, JSP) 2. Infrastructure testing - Servers - Routing equipment - VoIP - VPN 3. Denial of Service testing ( Dangerous! )
* Code audit is generally not billed the same way as regular pen-tests. Pen-tests are completed with a time limit. Code audit generally requires more time and will be billed accordingly based on the complexity, language, and size of the program.
The above list is just an example/rough list of things offered. Please do not hesitate to contact us and see what we can do for you. ---------------------------
I feel it is necessary to state the following:
A Penetration Test is not always a 100% complete assessment. It is generally performed with a time limit that's decided by the customer. Because of this, we will attempt to discover and probe as much as possible with the given time but things *can* be missed. If you'd like a deeper audit, we are more than happy to offer it. In the past, we've offered customers the option to have a full day audit as opposed to the regular 2-3 hours. It should be noted, however, if you only have a simple web application and a few servers, paying for the full audit may be overkill. Or it may be just what you need. Every situation is different.
Thanks in advance for reading this and we hope to serve the Bitcoin community as best as we can.
References and Resumes available. Reference list is extremely truncated due to NDAs. Reference list will not contain anything related to the company/IP addresses/findings/etc.
|