RedTeam Pentesting offers individual penetration tests, short pentests, performed by a team of specialised IT security experts. Hereby, security weaknesses in IT systems (e.g. networks, applications or devices) are uncovered and can be remedied.
As there are only few experts in this field, RedTeam Pentesting wants to share its knowledge and enhance the public knowledge with research in security related areas. The results so far are public security advisories which gained national and international attention.
In contrast to many other companies, RedTeam Pentesting specialises in pentests. A detailed description of pentests can be found on the pentest pages, frequently asked questions are answered in the FAQ section.
If there are any further questions, do not hesitate to contact us via email, fax or phone.
To stay up to date with news from RedTeam Pentesting you can subscribe to the following RSS feed.
News
- New advisory released: STARFACE: Authentication with Password Hash Possible. -
- Several advisories for vulnerabilities in the open-source software Pydio Cells released: Unauthorised Role Assignments, Cross-Site Scripting via File Download, Server-Side Request Forgery. -
- Today we released our newly developed program resocks. The accompanying blog post covers its usage and technical details. -
- Our new blog post describes the approach to integrate our new printer in our office infrastructure aiming to meet our specified security requirements. -
- Jens Liebchen held the talk “Physical Security – Wenn Türen zu Firewalls werden” on 7 February 2023 at the Chair for IT Security Infrastructures of the Friedrich-Alexander-Universität Erlangen-Nürnberg. The German language slides are available for download under Publications. -
- New advisory released: Skyhigh Security Secure Web Gateway: Cross-Site Scripting in Single Sign-On Plugin. -
- Alexander Neumann held the talk „Mitbringsel aus dem Alltag: Star Wars in der niedersächsischen Provinz” at the event “Studierende treffen Alumni und Unternehmensexperten” at the FH Aachen University of Applied Sciences. The German language slides are available for download under Publications. -
- The German TV show WDR Lokalzeit Aachen reported about our work and our new office. -
- New advisory released: Missing Authentication in ZKTeco ZEM/ZMM Web Interface. -
- Our new blog post introduces and covers common use cases of pretender, a new name resolution sidekick for relaying attacks. -
- RedTeam Pentesting has a new member: Roman Karwacik reinforces the team as a new penetration tester. -
- New advisory released: Credential Disclosure in Web Interface of Crestron Device. -
- Our new blog post describes our approach to discover a backdoor in the Auerswald COMpact 5500R PBX. -
- Several advisories for Auerswald devices released: Auerswald COMfortel 1400/2600/3600 IP Authentication Bypass, Auerswald COMpact Privilege Escalation, Auerswald COMpact Arbitrary File Disclosure, Auerswald COMpact Multiple Backdoors. -
- On 21 October 2021 Jens Liebchen will give the German language talk “IT-Sicherheit: Unterwegs zwischen zwei Welten” at 14:30 o'clock at the Technologiezentrum Aachen (powered by Techniker Krankenkasse). Register at konferenz@tza-aachen.de in order to participate. The 3G rule applies. -