Penetration testing with clear, practical next steps.
Secure Steps tests web applications, mobile apps and infrastructure, explains what each finding means for your business, and helps your team fix it, for organisations in Tunisia and beyond.
Services
Security testing for the systems your business runs on.
Every engagement gives you a clear view of risk, a plain explanation of impact, and a remediation path your team can act on.
Web applications
Penetration testing of web apps, APIs and login flows for injection, access-control and business-logic flaws.
Mobile apps
Testing of mobile apps and their back-end APIs, from local data storage to authentication and tampering.
Infrastructure
External and internal network and server testing for exposed services, weak configurations and attack paths.
How Secure Steps works
From uncertainty to a clear next move.
01 / Scope
Start with the question, system, product area, or finding that needs attention now.
02 / Analyse
Investigate the technical behaviour, confirm impact, and separate noise from the issues that actually matter.
03 / Remediate
Provide guidance that supports implementation, validation, and follow-through rather than just a report.
Insights
Latest writeups and analysis
Step-by-step walkthroughs of real attack chains, each ending with what defenders should do next.
-
Clean Sweep — ECOVACS CGI Command Injection Timing Oracle | NNS CTF
Detailed NNS CTF IoT walkthrough covering firmware extraction, SetFct command injection, timing-oracle design, verification, and defensive lessons.
-
Light-Weight Encryption — Lattice Attack | NNS CTF
Detailed NNS CTF cryptography walkthrough explaining the weak LWE construction, modular lattice, error recovery, CVP step, and equation-level verification.
-
Min beste venn — PCAP Bit Encoding | NNS CTF
Detailed NNS CTF forensics walkthrough explaining how HTTP request multiplicity encoded bytes and how to decode the PCAP reproducibly.