I will perform API penetration testing and security audit
Your trusted partner in cyber security
About this Gig
Secure your API before attackers find the vulnerabilities.
I will perform a manual API penetration test and security audit based on the OWASP API Security Top 10 to identify vulnerabilities, authorization issues, authentication weaknesses, business logic flaws, and sensitive data exposure.
What I will test:
- API authentication & authorization
- Broken Object Level Authorization (BOLA/IDOR)
- Broken Function Level Authorization (BFLA)
- JWT & session security
- SQL Injection & NoSQL Injection
- Excessive data exposure
- Rate limiting & API abuse
- Input validation
- Security misconfigurations
- Business logic vulnerabilities
- Sensitive data exposure
- Other OWASP API Security risks
What you will receive:
Detailed PDF penetration testing report
Vulnerability severity and risk rating
Step-by-step Proof of Concept (PoC)
Affected endpoints and evidence
Clear remediation recommendations
Executive summary for management/developers
I use manual security testing techniques to go beyond automated vulnerability scanners and help you understand and fix the actual security risks in your API.
Authorized testing only. Please provide written authorization before testing.
Testing application:
API
Device:
PC
•
Linux
