zauth
862 posts











Incredible feedback from @zauthx402's Deep Scan. While it wasn't able to access the admin endpoints (and there are many), it made a good suggestion on how to rectify possible exposure. IDOR is something I knew about, and the endpoints are protected, but it's good practice not to use sequential IDs. I'm going to use the feedback to fix the high, medium, and some of the low priority items. I've already done security scanning by myself, but their findings were of much higher quality.

Now Running @zauthx402's Deep Scan for Bloxx Builder! Fingers crossed :) zauthx402.com/vector

I do really like Vector from $ZAUTH. You paste a URL, verify ownership and it analyzes your web app stack and surfaces vulnerabilities. Blackbox pentesting, no setup, low cost, fast execution. Clear value if you’re shipping and need quick security checks.









Developers can now pay for security directly on @solana. Our live agentic pentest thinks like an attacker. Vector creates accounts, logs into your app, probes the full attack surface, and finds vulnerabilities before someone else does. zauth can save your business in minutes.











