Security reviews

Penetration testing & security reviews in Nigeria

I take on a small number of security reviews alongside my research, for teams in Lagos, across Nigeria and elsewhere in Africa. My focus is the flaw class behind every critical issue I have reported: broken access control.

WEB APPLICATIONS

Web application penetration test

A manual test of your web platform against the OWASP Top 10, with most of the time spent where real breaches start: access control, session handling and business logic.

  • Authenticated and unauthenticated testing
  • Role and tenant separation
  • Findings ranked by real-world impact
APIS & MOBILE BACKENDS

API access control review

A focused review of the API behind your web or mobile app, checking that every endpoint verifies not just who the user is, but whether they may touch that specific record.

  • IDOR and object-level authorisation
  • Lookups keyed on emails, phone or account numbers
  • Rate limiting and enumeration
BEFORE LAUNCH

Pre-launch security review

For fintech, education and government-facing platforms about to go live: a review of the authorisation model and the endpoints most likely to leak customer data on day one.

  • Authorisation design review
  • Exposed endpoints and data paths
  • A short, prioritised fix list
How it works

Written permission first, a fix list at the end

  1. 01

    Scope

    We agree in writing what is in scope, the test window and who to contact. Nothing is tested without written permission.

  2. 02

    Test

    Manual testing, with minimum necessary access to real data and no destructive actions.

  3. 03

    Report

    A clear report your engineers can act on: each finding with impact, evidence and a specific fix.

  4. 04

    Retest

    Once fixes are in, I check them again and confirm what is closed.

Why access control

Broken access control is number one on the OWASP Top 10, and it is the flaw I have found in a federal registry, a university platform and a payments app. It passes normal testing because developers only ever request their own data. Finding it takes someone deliberately asking for records that belong to somebody else.

See the disclosures and the write-ups.

Availability is limited. Tell me about your platform and timeline.

Request a review
Request a review
Get in touch

Hiring, or working on a hard data problem?

I am open to engineering roles and contract work in document AI, data pipelines and web. Vulnerability reports go to the security address.