I will perform manual API penetration testing with owasp top 10 report and poc
Penetration Tester and Cloud Security Specialist
About this Gig
Your API is the #1 target for attackers. Over 80% of modern breaches start at the API layer; one broken endpoint can leak your entire customer database. I don't run automated scanners and call it a day. I hunt real vulnerabilities the way an actual attacker would, then hand you a report your developers can actually fix.
With hands-on experience in offensive security and cloud environments, I specialize in REST, GraphQL, SOAP, and cloud-native APIs (AWS, Azure, GCP, Kubernetes, Serverless).
What I Test:
- OWASP API Top 10
- BOLA / IDOR & Broken Authorization
- JWT, OAuth2, API Key flaws
- SQLi, NoSQLi, SSRF, XXE, Command Injection
- Business Logic & Race Conditions
- Rate Limiting & DoS resilience
- Cloud misconfigurations (IAM, S3, Secrets)
What You Get:
- Executive + Technical PDF report
- CVSS 3.1-scored findings
- Proof of Concept for every issue
- Step-by-step remediation guidance
- Free retest after fixes
- NDA signed on request
Why Work With Me:
- Manual + Automated testing, not scanner dumps
- Real-world attacker mindset
- Developer-friendly, no-fluff reports
- 100% confidential & responsible disclosure
Message me before ordering; every API is different. Let's secure yours before the bad guys find it.
My Portfolio
FAQ
Is my API and data safe with you?
Absolutely. I sign an NDA upon request, work in an isolated environment, and permanently delete all data after delivery. Your API, credentials, and findings never leave my secure workstation — 100% confidentiality guaranteed.
Will testing break my production API or cause downtime?
No. I use non-destructive testing techniques by default. If any test carries risk (like DoS or rate-limit stress), I'll ask first and recommend a staging environment. Your production stays safe and online.
What if you find no vulnerabilities — do I still pay?
Yes, and here's why: you're paying for expert validation, not just bugs. You'll receive a full report with methodology, coverage, and hardening recommendations—proof that your API passed a real security audit. That's compliance-ready evidence.
Do you provide a retest after I fix the issues?
Yes. Standard includes 1 free retest round; Premium includes 2. After you apply fixes, I re-verify every finding and send an updated report confirming the fixes — so you know your API is actually secure.
What do you need from me before starting?
Four things — API documentation (Swagger/Postman), test credentials (2+ roles), in-scope domains/IPs, and written authorization to test. I only test APIs with explicit permission. This protects both of us legally.

