Skip to content
Noroxi

Infrastructure and network penetration testingOnce someone is in, how far can they go?

We start with what’s visible from the outside, then measure what an employee—or a compromised device—can reach from the inside.

Duration
5–15 business days
Standard
PTES · NIST SP 800-115
Deliverables
Report, readout and retest within 30 days

What we test

  1. 01

    External surface

    Internet-facing services, VPN and remote access.

  2. 02

    Active Directory

    Privilege structure, password policy and delegation.

  3. 03

    Segmentation

    Traffic allowed between network segments.

  4. 04

    Endpoints

    Server and client configuration, patch levels.

  5. 05

    Wireless

    Separation of guest and corporate networks.

  6. 06

    Lateral movement

    Paths from a single device to critical systems.

Vulnerabilities we often find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • Over-privileged service accountsCritical
  • Flat network with no segmentationHigh
  • Unpatched internet-facing serviceHigh
  • Weak password policyMedium
  • Exposed management interfacesMedium

This is how a finding is delivered.

Clear enough for a developer to fix on their own. Plain enough for an executive to grasp at a glance.

NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

How it works

  1. 012–3 days

    Scoping

    IP ranges, testing window and access method.

  2. 022–5 business days

    External testing

    Your entire internet-facing surface.

  3. 033–10 business days

    Internal testing

    Access from inside the network, AD and lateral movement.

  4. 043 days + 30 days

    Report and retest

    An attack path map, followed by a retest.

Frequently asked questions

Do you need to come on-site for internal testing?
No. We can run it remotely, either with a test device we ship to you or over VPN.
Will production systems be affected?
Nothing that could disrupt service happens without written approval, and load-heavy scans are scheduled outside business hours.
Is the Active Directory review separate?
No, it’s a standard part of internal testing.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing