01
Penetration testing
Web, mobile, API, and cloud targets tested the way an adversary would. Findings are written up so your engineers can fix them, not just file them.
Offensive Security
Before BlockShift built anything, its founders spent years breaking things, responsibly. Our vulnerability research has been acknowledged by some of the most attacked platforms on the internet. That adversarial mindset is available to clients directly.
Security research acknowledged by
Verified findings
Every vulnerability we reported through bug bounty programs at Medium severity or above, grouped by class. Open a card to see how we hunt for that class and which vendors fixed what we found. Undisclosed reports are described by class, not title, and private programs are not named.
HackerOne
Bugcrowd
Google Bug Hunters
Meta Bug Bounty
Reading or changing data that belongs to someone else.
Booking.com · Hyatt Hotels · Inflection
What it is
The server checks that you are logged in but not that the record you asked for is yours. Swap an identifier and you are looking at another customer’s fleet, listing, document, or organization. It is the most common serious bug in multi-tenant products, and the one internal teams most often miss because every individual screen looks fine.
How we find it
Resolved by
Getting in, or staying in, without the credentials that should be required.
Assembla · Google · Inflection
What it is
Login, two-factor, password reset, invitations, and email change each make an assumption about what can be trusted. When one step trusts something another step can change, the whole chain gives way: a reset token that outlives an email change, a second factor that a reused browser skips, a mobile client that never asks for it at all.
How we find it
Resolved by
Input that comes back as code: in the browser, in a spreadsheet, in a macro.
Inflection
What it is
Anything the product stores and later renders, exports, or embeds is a candidate. Stored cross-site scripting lets one user run script in another user’s session; a formula in a CSV export runs when an administrator opens it in a spreadsheet. Rich-text and macro features are the usual entry point because they render HTML on purpose.
How we find it
Resolved by
Making the server, or another user’s browser, send a request it should not.
Dynatrace · Superhuman (formerly Grammarly) · Google
What it is
Server-side request forgery turns a URL-fetching feature (a webhook, an integration, a link preview) into a proxy into the vendor’s own network, where cloud metadata endpoints hand out credentials. Cross-site request forgery makes a logged-in user’s browser perform an action, such as deleting their account, from a page the attacker controls.
How we find it
Worked example: Dynatrace, Critical (10.0)
Dynatrace’s custom integration webhook refused 301 and 302 redirects but followed a 303. A webhook pointed at a page that answered 303 to the AWS metadata service returned the instance’s IAM credentials in the test-notification response. Dynatrace fixed it, paid its maximum bounty, and disclosed the report.
Read the disclosed report ↗Resolved by
Credentials in public code, internal tools reachable from the internet.
SEEK · Spotify
What it is
Large engineering organizations leak at the edges: a password committed to an open-source repository, a build-artifact server that answers to anyone. Nothing is exploited in the classic sense. The door is simply open.
How we find it
Resolved by
The product does what it was built to do, and that is the problem.
Haufe Group · Kyivstar · The Iconic
What it is
Race conditions, invitation links that can be forwarded, a login form served over plain HTTP. None of these is a coding error in a single line. They are decisions about ordering, trust, and defaults that only fail when someone pushes on them.
How we find it
Resolved by
Private programs are invite-only or were redacted by the customer, and their terms do not allow us to name them. Severity ratings are the program’s own, as recorded on HackerOne (Medium and above) and Bugcrowd (P3 and above). Google VRP does not publish a severity, so those rows show fix status instead.
What we offer
01
Web, mobile, API, and cloud targets tested the way an adversary would. Findings are written up so your engineers can fix them, not just file them.
02
Contract review by engineers who deploy to Ethereum, Solana, Polygon, and Arbitrum in production. We audit what we know how to build.
03
A structured map of what your product exposes (endpoints, integrations, secrets, assumptions) and which of it an attacker would reach for first.
04
Ongoing access to the founders for threat modeling, architecture review, and incident questions. Security judgment on tap, without a full-time hire.
Tell us what you are shipping and what you are worried about. We will tell you exactly how we would approach it.
Book a callor write to hello@blockshift.com.pk