Security seen from the other side.

Offensive security researcher. I find the flaws in your web infrastructure before an attacker does : exposed secrets, vulnerable configurations, accessible source code. Then I give you the means to fix them.

Request an audit →View findings
fraudless — reconlive
$
test your domain right there
0+
Companies contacted
0
Confirmed CVE / findings
// 01

What I look for.

A web infrastructure exposes far more than people think. Four families of vectors concentrate most of the real risk. Invisible until someone looks from the right side.

01

Exposed secrets

Public .env files, plaintext credentials, API keys and tokens forgotten in front-end code. The most dangerous secret is the one the developer thinks is private.

.envAPI keyscredentialsSMTP tokens
02

Server configuration

Missing security headers, permissive CORS, misconfigured TLS, exposed services. The door wasn't forced. It was already open.

headersCORSSSL/TLSdirectory listing
03

Sensitive files

Forgotten backups, accessible .git repositories, production source maps, SQL dumps. An app's complete source code, accessible in a single request.

.gitbackupssource mapsSQL dumps
04

Application vulnerabilities

Injections, missing authentication, IDOR, bypassable business logic. Where the developer assumed without ever verifying.

XSSSQLimissing authIDOR
// 02

Real flaws. Real companies.

Three discoveries among others, reported under responsible disclosure and fixed. Names anonymized in accordance with confidentiality commitments.

CRITICALPublic Git repository exposed without authenticationFIXED
Digital media network, 15 production sites

With a single command, it was possible to download the entire source code of 15 production sites. The repository contained: an active Google Cloud private key giving access to analytics data for 50 million monthly visitors, root server deployment credentials, and a JWT key enabling identity theft of any user account on the network.

ImpactFull access to the network's infrastructure. Personal data of 600+ people exposed in migration files. Constituted GDPR breach requiring CNIL notification.
CRITICALAgency vulnerability → 38 client projects exposedFIXED
Media and e-commerce group

The flaw was at their technical agency, not directly at the client's end. An accessible Git repository on the agency's server contained configuration files for dozens of client projects. Among the secrets found: an active live Stripe key, a CRM access key giving access to the full subscriber contact database with personal data, and user account management credentials.

ImpactFull access to the subscriber database, payment data and account management. An attacker could list paying subscribers, their partial banking information and initiate fraudulent refunds.
HIGHPublic endpoint exposing the complete application source codeFIXED
Mobile transport application

A public URL gave access to the entire application source code with no authentication required. Analysis of the code revealed that the app's chat database was openly readable by anyone on the internet: conversations between drivers and passengers were visible in real time. The code also contained unprotected SQL injection flaws in the mobile API, and third-party service access keys stored in plaintext.

ImpactUser travel privacy was compromised. The API flaws theoretically allowed access to all platform data: profiles, ride history and payment data.
// 03

Three audit tiers.

From a quick diagnosis to full support. Every audit ends with an actionable report, prioritized by real impact.

DISCOVERY

LITE Audit

€49–99

Quick diagnosis of your external exposure. Ideal for a first assessment.

  • External attack surface scan
  • Detection of exposed secrets and files
  • Server configuration check
  • Concise report with priorities
Request a quote
// 04

Latest articles

Research, vulnerabilities and security tips.

View all articles
// 05

Describe your exposure.

Response within 24 business hours · free initial analysis

1
2
3

Step 1 · Your need

Frequently asked questions.