I will perform API penetration testing and security audit

Estonia

I speak English, Persian, Azerbaijani, Turkish

Your trusted partner in cyber security

Hi! I am Farzad, a Cybersecurity Engineer specializing in penetration testing, vulnerability assessments, and advanced threat mitigation. I help businesses secure web applications, networks, and emer...
About this Gig

Secure your API before attackers find the vulnerabilities.

I will perform a manual API penetration test and security audit based on the OWASP API Security Top 10 to identify vulnerabilities, authorization issues, authentication weaknesses, business logic flaws, and sensitive data exposure.

What I will test:

  • API authentication & authorization
  • Broken Object Level Authorization (BOLA/IDOR)
  • Broken Function Level Authorization (BFLA)
  • JWT & session security
  • SQL Injection & NoSQL Injection
  • Excessive data exposure
  • Rate limiting & API abuse
  • Input validation
  • Security misconfigurations
  • Business logic vulnerabilities
  • Sensitive data exposure
  • Other OWASP API Security risks

What you will receive:

Detailed PDF penetration testing report

Vulnerability severity and risk rating

Step-by-step Proof of Concept (PoC)

Affected endpoints and evidence

Clear remediation recommendations

Executive summary for management/developers

I use manual security testing techniques to go beyond automated vulnerability scanners and help you understand and fix the actual security risks in your API.

Authorized testing only. Please provide written authorization before testing.

Testing application:

API

Device:

PC

Linux