Pentest Your Web
App In Hours.
Hound uses AI to attack your app like a real hacker would, automatically finding problems other tools miss.
Security at Inference Speed
Built for Offense
- Uses a Real Browser
- Logs In and Completes MFA
- Tests Behind Auth
- Reasons About Business Logic
- Chains Multi-Step Attacks
- Adapts to What It Finds
Reports That Drive Action
Security Assessment — cyberhound.dev
Executive Summary
We tested the security of cyberhound.dev and its backend API (api.cyberhound.dev). The website is a marketing page protected by a password gate, and the API handles pentest request submissions.
Critical Issues
1. API crashes on unexpected input, bypassing bot protection.
Sending non-text values to the pentest request API causes the server to crash with a 500 error. These crashes happen before the bot-detection check runs.
2. Password gate can be brute-forced without rate limiting.
The HTTP Basic Auth gate has no lockout or rate limiting. We performed 1,155 login attempts without being blocked.
Business Impact
Unauthorized access: The default password grants access to the full website and reveals backend API details, expanding the attack surface.
Guardrails Protect Your App
Your Findings Are Secure
FAQ
Enter your domain and where to send your results. We'll review your app, reach out if we need to coordinate, and start testing.
The full OWASP Top 10, known CVEs across your stack, and business logic flaws. Hound chains together weaknesses the way an attacker would.
After you submit your domain, we'll send you a DNS verification key. Add it to your DNS records and we'll start testing. This ensures we only test sites you own.
Yes, and it handles MFA too. Hound logs in, navigates your app, and tests pages behind authentication. We'll coordinate account setup with you before your first run.
Absolutely. Every command and script is reviewed in real-time by an independent safety layer. Dangerous operations are blocked before they run. Hound proves vulnerabilities exist without causing damage.
Hound works with or without a WAF. If you'd prefer to whitelist us, reach out and we'll provide an IP you can add to your allowlist.
Still have questions? Reach out at support@cyberhound.ai