You received an email from me.About a security issue.Take 60 seconds.Check who I am.

I'm Max, an independent security researcher.

Ethical hacker / White Hat / Good guy / You name it.

Long story short: I'm here to help.

Max

Who I am

Based in the Netherlands.

Running WebSafety Ninja since 2018.

KVK 72801980.

Notified 12,000+ companies (big and small) about exposed data since 2018.

Hall of Fame

Acknowledged in the security hall of fame of:

Philips · SAP · Exact · Razorpay · Rackspace · HealthUnlocked · HyperNode

Not my first time

"Max helpfully identified an internal configuration infoleak issue with one of Rapid7's web assets, which we were able to quickly confirm and remediate thanks to his report."

Tod Beardsley

Director of Research, Rapid7

Questions you're probably asking right now

I admit, this looks like a scam. Unknown person contacts you about security.

Do you own research: Maksym Bendeberia and/or WebSafety Ninja.

No. The report is free, no strings attached. Rewards welcome only if that's what you want to do AFTER you see the report.

Passive checks on what's publicly exposed.

I'll send you a plain-text report: what's wrong, how to fix it. We could schedule a call if you're interested.

That's fine, I follow the CERT/CC collaborative vulnerability coordination process and report to the relevant regulatory authorities in your country instead. You don't have to trust me — but the issue needs fixing, one way or another.