Services

Security analysis

Source code and firmware review, and vulnerability research. We read the code, work out what someone could do with it that they should not be able to, and write it up in a form your developers can act on.

Ask about a review

What we look at

  • Application code. PHP applications, Laravel and framework-less alike, and the scripts that grow up around them. Injection, broken access control, unsafe file handling, and the logic errors automated scanners tend to miss.
  • Device firmware. Firmware for embedded devices: how it parses what it is sent, what it trusts, and what it does when the input is not what it expected. Most of our current independent research is here.
  • Forum software and its add-ons. Plugins, custom modifications and integrations, which on a mature site are usually the least reviewed code it runs.
  • Systems that cannot simply be patched. Working out what an old install exposes, and how much of it can be closed off with a reverse proxy, request filtering and access control without breaking the site.
  • Independent research. We also look at software and firmware we do not maintain, on our own initiative, and report what we find privately to the vendor.
  • After a compromise. Getting the data back, rebuilding on a clean system, and closing the way in where it can be found. One recovery we have written up.

How it goes

  1. Agree the scope: which code, which version, and anything that is off limits.
  2. Read it. Tooling helps with the first pass. Most of the time goes into reading.
  3. Reproduce each finding before reporting it, on a copy of the system or a test device, and never on anything live.
  4. Write it up: what is wrong, how serious it is, how it can be reached, and what to change.
  5. Check the fix, if you want a second look once it is in.

What this is not

We do not offer penetration testing, and we do not issue certificates, attestations or compliance reports. If a regulator, an insurer or a customer contract requires a signed audit, you need a firm accredited to provide one.

A review that finds nothing is not proof that nothing is there, and the report will say so.

Disclosure

Anything we find in software we do not maintain is reported privately to its maintainer first. We publish nothing until they have had a reasonable time to fix it, and we follow the vendor's own disclosure policy where it has one.

Findings from client work belong to the client. We do not publish them or discuss them without permission.

Why us

We started building for the web in 1996, and over the years wrote more than 300 custom products for the vBulletin framework. Security review is mostly careful reading of code somebody else wrote, often without documentation, and that has been the day job for a long time.

We also run production systems. A recommendation from us takes into account what it costs to deploy the fix on a live site, and which fixes can wait.

More about us →

Have code that needs a second look?

Tell us what it is, roughly how large, and what worries you about it. You do not need a threat model before getting in touch.

Start a conversation