I do mean pentesting. More specifically, for a relatively small fee I'll conduct a security evaluation using the most commonly used tools, of both your application and the server(s) that it's hosted on. I'll then provide you with specific results for all of the tests I do.
Sir, we can talk here, no need for a PM. How much is that "relatively small fee" you talk about?
Ofcourse I just want you to tell me your results first, wait/help me fix the problems, and then release your findings publicly after.
On my view we will all win if we do it like that.
My fee will be between .5 and 2 BTC depending on how large your site is; if you wish to use my services I will provide you with a quote. Of course I will also provide a list of the tests I'm going to use as part of the agreement. Upon delivery of the results, I will include recommendations about how to fix any problems, as well as detailed descriptions of all of my findings. I will not release the findings publicly, however if you wish to do so, you will have full right to.
I'm happy to discuss this in general terms here, but for negotiation of prices and our agreement, I would like to do it through PM or email.
OK. Can you please send me a quote to [email protected] ?
As to how big the site is, just login using one of your accounts which supports OpenID and see for yourself.
There is one other part which I wish to audit, the API, so you can count on the usual exchange API functions(balance, sell, buy, withdraw, deposit, order book, ticker). I will provide you with API access, ofcourse.
Sure. Give me a few days to check out the site and create a quote based on what I think needs to be tested.