Cross-user order receipt access
GET /api/orders/1042 → 200
authenticated as user A, response contains user B's order record
Customer data exposed across account boundaries.
Enforce object-level authorization on every record fetch (CWE-639).
Permissioned attack simulation
TrojanStrike runs a real, permissioned intrusion against your own website — rate-limited, non-destructive, every request logged — and shows you exactly how far an attacker would get, with the evidence and the fix. Your first full strike is free.
How it works
One continuous operation, from first signal to final judgment. Scroll — watch it unfold.
Your target assembles out of raw signal — every route, header, and asset catalogued, ownership verified, before a single probe is sent.
The crawler unfolds the monolith into a lattice of endpoints — pages, forms, API calls — and walks it branch by branch, marking the points worth pressuring.
Thousands of permissioned probes fire at the lattice. Almost everything deflects. What pierces is captured as evidence — read-only, non-destructive, every request logged.
Everything the strike learned converges into a single verdict — one word, the evidence behind it, and the fix.
From click to verdict
This is the entire engagement — what you do, what TrojanStrike does, and exactly what lands in your hands at the end.
A finding, exactly as reported
Not a mock-up. Every finding in your report carries the verdict, the proving request, the impact, and the fix — like this one.
Open a full sample report →GET /api/orders/1042 → 200
authenticated as user A, response contains user B's order record
Customer data exposed across account boundaries.
Enforce object-level authorization on every record fetch (CWE-639).
“I found something suspicious.”
A maybe. A severity score. A ticket you learn to ignore.
“I tried it, and here's the evidence.”
A proof. A request log. A fix you can act on today.
Verdicts
No scores, no hedging. A single word that tells you exactly where you stand — backed by the evidence that produced it.
Breached, and data walked out the door.
Confirmed data extraction, read-only.
The attacker got in.
A critical or high finding holds up.
A partial foothold — the door still held.
Medium-severity issues confirmed.
Your defenses held the line.
Nothing exploitable found.
Engine room
Each capability below runs against your stack and reports only what it can prove. Nothing is inferred twice and nothing is exaggerated once.
Discovers the injection context, then proves it with a bounded, read-only data pull.
Substitutes operator objects into JSON bodies and measures the record-set differential.
Plants a unique callback address; a hit from your server is the only admissible proof.
Replays alg=none and RS256/HS256 confusion forgeries against your own session oracle.
Re-requests objects across ownership boundaries and flags foreign data in the response.
Retries extension-filtered reads with double-encoded null bytes to expose filter bypasses.
Drives a headless browser with an inert markup canary and confirms it lands as live DOM.
Probes common autoindex directories and classifies any sensitive entries it finds.
Reads your shipped bundles for hardcoded credentials and known key formats — redacted, always.
Detects edge mitigation and suppresses findings whose evidence a block page could have faked.
Rules of engagement
A scan cannot start until domain ownership is attested and re-verified live. There is no bypass and no exception.
Proof-of-extraction stops at the minimum that demonstrates impact — SELECT-only SQLi, an allowlist of identity commands, nothing destructive, ever.
Abort any scan mid-flight. Every request we send is logged for your review, and you can purge the data at any time.
Permissioned by design
Prove it's yours — 60 seconds. Then the recon fires itself. The legal gate is the product: it's how you know the attack is real, and how the world knows it's welcome.
Drop a meta tag or a DNS record on your domain. One method, about a minute, done once.
The moment verification lands, a passive RECON scan launches automatically — no button to find.
Your surface map streams into a live report. The first verdict is already on its way.
Pricing
Pay for verdicts, not vibrations. Every price in AUD — no seats, no tiers of tiers.
The surface map, on the house.
The full active assault, once.
The assault, behind your login.
The watch that never stands down.
Need volume? 5 strikes A$1,795 · 10 A$3,390 — for consultants and teams.
What you run between penetration tests — not a replacement for one.