Penetration testing that ends with fixes you can verify.
Rosec Cyber tests web applications, APIs, and networks, then writes findings that developers and decision-makers can both act on. When you fix something, we test it again and tell you whether the fix holds.
Password reset token still works after it is used
High- Affected
POST /api/account/reset- What we saw
- A reset link can be replayed after the password has already been changed, so anyone who sees the link later can take over the account.
- Evidence
Request 1: 200 OK, password changedRequest 2, same token: 200 OK, password changed- Fix
- Invalidate the token on first use and expire unused tokens after 15 minutes.
- Retest
- Fixed and verified. Second request now returns 400.
Services
- Penetration testing
- Web applications, APIs, and networks, tested within a scope and rules of engagement you approve in writing. Manual testing comes first and tooling supports it.
- Application security
- Review of how your software is designed and built, with attention to authentication, authorization, and how data is handled. Recommendations are written for the developers who will make the change.
- Security awareness training
- Phishing simulations, tailgating tests, and physical intrusion assessments, followed by short training built from what happened at your site.
- Retesting
- After you remediate, we test the same issues again and report which fixes hold and which need more work.
How an engagement runs
Scope
We agree on targets, dates, and rules of engagement in writing before any testing starts.
Recon
We map what is exposed, starting with passive sources and moving to active checks inside scope.
Test
We probe for weaknesses and confirm each one with evidence, so every finding is reproducible.
Report
You get a plain-language summary for leadership and technical detail with fixes for your engineers.
Retest
Once you have fixed findings, we verify them and update the report.
About
Rosec Cyber is led by Cody Smith, a security consultant in Georgia with more than 15 years in IT operations and systems management. That operations background shapes the reports: they are written for the people who have to schedule, fund, and ship the fixes, as well as the engineers who write them.
Cody also does bug bounty research and builds open security tooling, which keeps the testing current with how real attackers work.
Certifications
- GIAC Certified Incident Handler (GCIH)
- GIAC Security Essentials (GSEC)
- GIAC Foundational Cybersecurity Technologies (GFACT)
- ISC2 Certified in Cybersecurity (CC)
Writing
Graybox is our newsletter on security for small and mid-sized organizations. It covers what happened, why it matters, and what a sensible response looks like, without the hype.
Contact
Tell us what you want tested and by when. We will reply with questions and a proposed scope.
Found a vulnerability in our site? Our security contact explains how to report it.