Skip to content
Noroxi

Web and API penetration testingWe find what scanners miss.

Automated scanners catch known signatures, not business logic flaws. We test your application by hand, the way a real user—and a real attacker—would.

Duration
5–10 business days
Standard
OWASP ASVS · PTES
Deliverables
Report, readout and retest within 30 days

What we test

  1. 01

    Authentication

    Passwords, multi-factor authentication, session and token handling.

  2. 02

    Authorization

    Role- and object-level access controls.

  3. 03

    Business logic

    Payment, discount, ordering and approval flows.

  4. 04

    API security

    REST and GraphQL endpoints, rate limiting.

  5. 05

    Input handling

    Injection, file uploads and server-side requests.

  6. 06

    Configuration

    Security headers, CORS, error messages and dependencies.

Vulnerabilities we often find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • Broken object-level authorizationCritical
  • Price or quantity can be tampered with mid-flowHigh
  • Insufficiently protected session tokenHigh
  • Login endpoint with no rate limitingMedium
  • Missing security headersLow

This is how a finding is delivered.

Clear enough for a developer to fix on their own. Plain enough for an executive to grasp at a glance.

NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

How it works

  1. 011–2 days

    Scoping

    We agree on the endpoint list, roles and test accounts.

  2. 025–8 business days

    Discovery and testing

    Manual testing; critical findings are reported the same day.

  3. 033 business days

    Report and readout

    Executive summary, technical report and a developer session.

  4. 04Within 30 days

    Retest

    Fixed findings are retested free of charge.

Frequently asked questions

How many days do we need for how many endpoints?
Roughly 5 business days for up to 50 endpoints. The real drivers are the number of roles and how complex your workflows are.
Do you need our source code?
No, we can work black-box. If you give us code access, we reach deeper coverage in the same amount of time.
Can you fit into our release cycle?
On annual programs, we schedule a short retest ahead of every major release.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing