I will perform API penetration testing and security assessment

C
cyber_services2
C
cyber_services2
Cyber Services

Level 2

About this gig

Your API is your biggest attack surface and the place most testers go shallow. I go deep.


Senior pentester (OSCP, OSWE, CBBH) specialized in REST and GraphQL security. I test the way real attackers and bug bounty hunters do, by hand, chaining small flaws into real impact.


What I test:

- Broken object-level auth (IDOR/BOLA) and broken function-level auth across every endpoint

- Mass assignment, excessive data exposure, and auth/JWT/OAuth flaws

- GraphQL introspection, batching, and rate-limit bypass

- Business logic, injection, and SSRF reachable through the API


What you get:

- A professional report mapping each issue to the OWASP API Top 10, with CVSS severity, raw proof,

  and step-by-step fixes

- An executive summary plus a developer-focused technical section

- One free retest after remediation


Send me your API docs (Swagger/Postman) or base URL and roles, and I will scope it and quote a fixed price before you order.


Respect third-party rights

Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.

Get to know Cyber Services

Cyber Services

Senior Red Team Operator and Penetration Tester OSCP, OSEP, CRTO

5.0(44)

Level 2

  • FromPakistan
  • Member sinceFeb 2024
  • Avg. response time1 hour
  • Last delivery2 weeks
  • Languages

    English, Urdu, Punjabi, Hindi
Hi, I am Abdullah, a Senior Penetration Tester and Software Engineer with 8 years of offensive security experience. I hold active OSCP, OSEP, CRTO, CRTE, and eCPPTv2 certifications. I specialize in complex adversary simulation and targeted penetration testing across Web, API, Mobile, and Active Directory environments. I am also a proficient developer in C#, C++, Python, and Java, allowing me to assist you in secure code development and architecture review. I deliver high-end, structural technical results for short or long-term projects within strict project timeframes.