
Niko Krek
Manual pentesting for web apps, APIs and AI generated code
Habilidades

Conheça meus serviços


Portfólio
Experiência profissional
Founder & Security Researcher
NEHILO • Autônomo
Dec 2025 - Present • 9 mos
Independent security-testing practice: manual web and API penetration testing, OSINT attack-surface reviews, second-opinion validation and retests. Runs coordinated-disclosure campaigns with independently validated findings. Practice site: nehilo.eu What I test by hand: broken access control (IDOR and BOLA, object ownership, privilege boundaries between roles); business logic such as refunds, discounts, quotas and state machines that can be driven backwards; payment and webhook flows including replay, signature verification and race conditions; authentication and session handling; and API specifics like mass assignment, object level authorisation and rate limits. Operational security engineering is a separate line of the practice: compartmentalised egress and identity architecture, attribution-resistant infrastructure, and leak-path analysis across traffic patterns, DNS, TLS fingerprints and document metadata. How engagements are run: signed scope, NDA and data-processing terms before the first packet, declared source addresses so the client's blue team can attribute every request and validate their own detection, and a timestamped action log for correlation. Client data stays in its own zone and is destroyed on schedule. A credential or access path found during a test is an exposure to report and rotate, never something to keep. Reports map to OWASP WSTG and the API Security Top 10. Every finding carries the exact request that reproduces it, impact demonstrated rather than asserted, and fix guidance developers can act on the same day. Retests are included. Most recent public work: a coordinated-disclosure audit of a production open-source platform. Fourteen findings in a single engagement, four of them in payment flows, fixes shipped by the maintainer.
Chief Executive Officer
PortierPay • Período integral
Nov 2024 - Dec 2025 • 1 yr 1 mo
Chief Executive Officer of a payments company. Owned product direction, client relationships and delivery end to end, with full profit and loss responsibility. Payments is where security stops being a severity label and starts being money. I sat on the operator's side of refund disputes and chargebacks, and watched money move through webhooks nobody was verifying. The failures that cost us were never exotic: provider callbacks accepted without signature checks, balance operations that behaved differently when two requests arrived at once, refund and cancellation paths that could be driven backwards through the state machine, and limits enforced in the interface but not in the API behind it. I also owned the access and compliance side: who could reach payment-adjacent data, how support staff were scoped, how processors and their sub-processors were vetted before they touched customer records, and what our own logs would actually prove if a dispute went the wrong way. That is the layer I now test hardest for clients, because I have had to explain those losses rather than write them up as findings.
Founder
Antinoon • Autônomo
Jan 2022 - Jul 2025 • 3 yrs 6 mos
Founder. Built and ran the company end to end: product, client relationships, team and delivery. Hands on with the infrastructure throughout, on the defensive side of the same problems I now attack: Linux fleets, DNS and mail, site-to-site VPNs, dual-stack IPv4 and IPv6, AWS networking and IAM, nginx and HAProxy behind Cloudflare, and Terraform for the parts that had to be reproducible. Running that stack is where the operational security habits came from. Segmenting access so that one stolen credential does not reach everything. Keeping the public attack surface deliberately small and knowing exactly what is on it. Watching what DNS records, TLS certificates and document metadata quietly disclose about internal structure. Treating key rotation and backup restores as something you rehearse rather than assume. It is also why an attack-surface review from me is concrete rather than theoretical. When a forgotten subdomain, an exposed management interface or a leaked internal hostname turns up, I know what it implies about the network behind it and what an attacker would reach for next.