🎯 Penetration Testing

Manual Testing by
Real Bug Hunters

We're active bug bounty hunters on HackerOne, Bugcrowd, and Intigriti β€” not compliance checkbox vendors. We test your web application the way a real attacker would, and we find what automated tools miss.

Scoped engagement Β· Evidence-backed report Β· Web application focus Β· Fixed-price

Manual testing where it counts

Automated scanners catch the obvious stuff. Manual testing finds the logic flaws, chained vulnerabilities, and edge cases that only a human attacker would notice.

🌐

Subdomain Enumeration & Takeover

Passive and active subdomain discovery across Certificate Transparency, DNS brute-forcing, and web archives. We manually verify takeover candidates β€” not just flag fingerprints.

πŸ”‘

Authentication & Session Testing

Broken auth flows, weak session token entropy, improper logout, OAuth misconfiguration, MFA bypass opportunities, and password policy gaps. We walk through every login and session path.

🧩

IDOR & Access Control

Insecure Direct Object Reference β€” can user A access user B's resources by changing an ID? Can a low-privilege user reach admin endpoints? We test every authorization boundary.

πŸ”—

CORS Misconfiguration

We test CORS headers for origin reflection, trusted-domain bypasses, and null origin acceptance. A permissive CORS policy on an API with authentication is credential theft waiting to happen.

↗️

Open Redirects

Open redirects are used to chain OAuth token theft, credential harvesting, and referrer-bypass attacks. We test every redirect parameter across the application.

πŸšͺ

Exposed Admin & Dev Endpoints

Admin panels, staging environments, debug endpoints, and developer tools inadvertently exposed to the internet. These are consistently among the highest-impact bugs we find.

πŸ“

Form Security & CSRF

Cross-site request forgery on state-changing actions. We verify CSRF token presence, token binding to session, and that double-submit cookie patterns are properly implemented.

⚑

Rate Limiting & Brute Force

Login, password reset, OTP, and API endpoints tested for rate limiting gaps. Missing rate limits allow credential stuffing, OTP brute force, and account enumeration.

Honest Scope β€” Web Application Focus Only

βœ“ What We Test
  • Web application authentication and session management
  • API endpoints and access control
  • Subdomains and takeover opportunities
  • Open redirects, CORS, CSRF
  • Exposed admin panels and dev environments
  • JS-embedded secrets and sensitive data
  • Rate limiting and account lockout gaps
  • IDOR and broken object-level authorization
βœ— Out of Scope for This Service
  • Internal network / infrastructure pentesting
  • Social engineering or phishing
  • Physical access testing
  • Code review (source code required)
  • Mobile app binary analysis
  • Complex SQLi or RCE exploitation chains

Need broader coverage? Contact us at hello@aluetion.com β€” we scope every engagement before pricing.

Structured. Scoped. Controlled.

Every engagement is scoped before it starts. No surprises on what we test or what we charge.

1

Scoping call

We define the target surface β€” which domains, subdomains, and endpoints are in scope. We agree on what's out of bounds and document it before a single request is sent.

2

Reconnaissance

Passive recon: DNS, CT logs, WHOIS, technology fingerprinting. We understand your public footprint before touching any endpoint.

3

Manual testing

We work through the in-scope surface manually β€” walking authentication flows, testing access controls, probing API endpoints, and checking every input the application exposes.

4

Evidence-backed report

Every finding documented with severity rating, HTTP request/response captures, reproduction steps, and a clear remediation recommendation. No theoretical findings β€” if we report it, we've demonstrated it.

5

Retest

After you fix the findings, we verify each one is closed and issue written confirmation. You don't just take our word for it β€” you see the evidence.

Practitioners, not checkbox vendors

We actively hunt on public bug bounty programs. Real programs, real triage, real findings β€” not just certifications.

πŸ… HackerOne β€” Active Researcher
πŸ… Bugcrowd β€” Active Researcher
πŸ… Intigriti β€” Active Researcher
πŸ‡ΊπŸ‡Έ DoD Vulnerability Disclosure Program
πŸ” OWASP Testing Guide methodology

Fixed-price, scoped engagements.

We scope before we price. Every engagement is defined upfront β€” no surprises.

Web App Pentest
$1,497

Single web application, defined scope

  • Authentication & session testing
  • IDOR & access control testing
  • CORS, CSRF, open redirect checks
  • Exposed endpoints & rate limiting
  • Subdomain recon + takeover check
  • Full written report with evidence
  • Severity-rated findings
  • Retest of all findings included
Start a Scoping Call

Know your web surface before attackers do.

We test your application with the same mindset we use on live bug bounty programs β€” because that's what actually finds real vulnerabilities.

Scope a Pentest

Web App Pentest $1,497 Β· Bundle with Security Audit $1,997 Β· Retest included