Ethical hacking and penetration testing
Security assessment of web applications, APIs, mobile applications and infrastructure to identify vulnerabilities and understand the risks behind them.
Who is it for?
For SaaS companies, development teams, banking and enterprise suppliers, and organizations preparing for compliance requirements or production launches.
Especially useful before launching a new system, after major development or infrastructure changes, when meeting partner security expectations, or when independent technical feedback is needed on the current security posture.
I am also open to professional cooperation, subcontracting inquiries and partnerships in application security, penetration testing and related areas.
Services:
-
External attack surface assessment
Security review of internet-facing systems, services and applications. The process identifies potential vulnerabilities, assesses the related risks and validates findings in a controlled environment. Testing can be performed with either a black-box or grey-box approach. -
Internal security assessment
Security assessment of internal networks, servers and user environments. The goal is to identify weaknesses in access control, network segmentation and potential privilege escalation paths, while evaluating risks that may arise from internal threats. -
Vulnerability assessment and validation
Vulnerability assessment using automated tools to identify known issues, misconfigurations and outdated software versions. Manual review and validation of automated findings ensures that the report contains real and relevant security risks only. -
OWASP-based application security testing
Security testing of web, mobile and thick-client applications based on the OWASP Top 10, OWASP Testing Guide and OWASP API Security Top 10 recommendations. Testing covers authentication and authorization mechanisms, business logic flows, data handling and the security of communication between applications and backend systems.
About
Security professional holding OSCP, CEH, BSCP and CompTIA Security+ certifications, with 10+ years of experience in security testing of financial, telecommunications and media systems. Vulnerabilities are identified through a combination of manual analysis and automated testing methods. I provide these services as a sole proprietor. CWES certification in progress.
Main focus areas:
- Web application penetration testing
- Mobile application penetration testing
- API security
- Authentication and authorization flaw testing
- OWASP-based vulnerability analysis
Methodology
Testing follows a structured methodology that combines manual analysis with automated assessments.
Service focus
LXDSec focuses on practical technical security assessments, penetration testing and vulnerability validation. The result of the assessment is a technical report that includes the identified findings, their risk ratings and recommended remediation steps. The service does not constitute a NIS2, ISO 27001 or other compliance audit, certification or legal preparation service, but it may support such preparation from a technical perspective.
Standards used
- OWASP Top 10
- OWASP Mobile Top 10
- OWASP API Security Top 10
How does the process work?
After the quote request, we get in touch and review the application, system or infrastructure to be tested together. During this discussion, we clarify the objective and scope of the assessment, the affected components, and what access, test accounts or permission levels are required.
If documentation, test environments or technical contacts are available, they help make planning more accurate. The process also includes agreeing on deadlines, testing windows, possible restrictions and pricing. If required, a non-disclosure agreement and other cooperation terms can also be agreed before the assessment begins.
Once the details are agreed, the assessment is performed and the results are delivered in a technical report, including remediation recommendations and risk ratings.
What does the report include?
The final report summarizes the results from both business and technical perspectives, so decision-makers and development teams receive actionable information.
- Executive summary of key risks and priorities
- Technical findings with reproducible steps and evidence
- Risk ratings and business impact interpretation
- Remediation recommendations and suggested mitigation steps
- Optional retest to verify implemented fixes
View the sample report to get a clear idea of what to expect as the outcome of an assessment.
References
Participation in project-based engagements involving security testing of web applications, API systems, internal infrastructure and mobile applications. The assessments covered financial, telecommunications, media and technology systems in environments of varying size and complexity.
- Hungarian banking web and mobile applications
- Applications for a television company
- Web and mobile applications for a Hungarian telecommunications company
- International banking and telecommunications web and mobile applications
- Internal systems of a security technology company
- University training materials and CTF challenge development
Experience in security assessments across financial, telecommunications and media environments.
Previous engagements included testing web applications, APIs, administration interfaces and internet-facing services. The assessments focused on authentication and authorization flaws, business logic issues, input handling weaknesses, configuration weaknesses and validation of known vulnerabilities.
Due to the confidential nature of client data, system details and specific vulnerabilities, references are presented at industry and technology level.
Contact
For penetration testing, vulnerability assessment or application security review inquiries, please use the email address below.
Pricing
Pricing is determined individually based on the scope of the assessment, the complexity of the systems and the effort required. For an accurate quote, please fill in the quote request form.
Request a quote
To request a quote, please fill in the online quote request form, or send an email to info@lxdsec.hu.
Not sure about the exact scope yet? A short discussion can help clarify it.