I will penetration testing service for web applications

India

I speak English, Tamil

Application Security tester

Hi, I'm Allen, a CEH v12-certified security professional with nearly 4 years of organisation-level experience in penetration testing and vulnerability assessment across web applications, APIs, mobile ...
About this Gig

Hi, I'm Allen, a CEH v12-certified security professional with nearly 4 years of organisation-level experience in penetration testing and vulnerability assessment across web applications, APIs, mobile apps and networks. My clients have been in banking, insurance, telecom and e-commerce.

In my full-time roles I've led end-to-end security testing for 35+ applications a year, from scoping and manual testing through reporting and retesting. I've found and documented 350+ high and critical vulnerabilities, with zero client escalations. I now bring the same process to freelance projects.

Services I offer

  1. Web application penetration testing: manual testing against the OWASP Top 10, covering injection, XSS, SSRF, RCE, authentication and authorization bypass, privilege escalation and business logic flaws.
  2. API security testing: REST and GraphQL, with a focus on BOLA/IDOR, broken authentication and authorization, and mass assignment.
  3. Mobile app security testing: Android and iOS, aligned with OWASP MASVS and the Mobile Top 10.
  4. Network vulnerability assessment: scanning and validation with Nessus, Nmap and OpenVAS, with false positives filtered out and findings prioritized by real risk.
  5. Security