I will perform professional API penetration testing and security assessment

F
faisal_mahmudx
F
faisal_mahmudx
Faisal Mahmud

About this gig

Professional API Penetration Testing & Security Assessment!


Is your REST or GraphQL API secure against real-world attacks? I provide manual API penetration testing based on the OWASP API Security Top 10 to find vulnerabilities before attackers do.


Services Include:

  • Authentication & Authorization Testing
  • BOLA (IDOR) Detection
  • Broken Authentication
  • JWT Security Review
  • Rate Limiting & Mass Assignment
  • SQL/NoSQL Injection
  • SSRF & File Upload Testing
  • Input Validation Flaws
  • Security Misconfiguration
  • Sensitive Data Exposure
  • Business Logic Testing
  • API Enumeration
  • GraphQL Security Assessment


You'll Receive:

  • Professional PDF Report
  • Executive Summary
  • Risk Rating (Critical/High/Medium/Low)
  • Proof of Concept & Screenshots
  • Technical Findings
  • Remediation Recommendations

Tools:

Burp Suite, Postman, OWASP ZAP, Nmap, ffuf, curl, Nuclei, jwt_tool, HTTPie, custom Python scripts.


Supported APIs:

REST, GraphQL, JSON API, Mobile App APIs, SaaS APIs, Internal & Public APIs.


I combine manual testing with proven tools for accurate results, low false positives, and practical fixes. Contact me first for multi-API or authenticated testing projects.


If you have any queries, feel free to ask me!

Respect third-party rights

Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.

Get to know Faisal Mahmud

Faisal Mahmud

CyberSecurity Specialist, Penetration Tester, Vulnerability Researcher!

  • FromBangladesh
  • Member sinceOct 2025
  • Avg. response time1 hour
  • Languages

    Bengali, English, Urdu
I'm Faisal Mahmud, a penetration tester who thinks like an attacker, so you don't have to worry like one. I specialize in Web App, API, & Network Security Testing using OWASP Top 10, ASVS & PTES methodologies — combining automation with deep manual testing to catch critical flaws that scanners (SQLi, IDOR, SSRF, broken auth) miss. You get evidence-backed reports with CVSS ratings, PoC screenshots, and dev-friendly remediation steps. NDA-friendly, fast turnaround, clear communication. Let's secure your product before someone else finds the gap.

My Portfolio