I will perform manual API penetration testing with owasp top 10 report and poc

Bangladesh

I speak English, French

Penetration Tester and Cloud Security Specialist

I'm a CyberSecurity professional specializing in Penetration Testing and Cloud Security. I offer security assessments for Web Applications, APIs, Networks, and Cloud Infrastructure, with a strong emph...
About this Gig

Your API is the #1 target for attackers. Over 80% of modern breaches start at the API layer; one broken endpoint can leak your entire customer database. I don't run automated scanners and call it a day. I hunt real vulnerabilities the way an actual attacker would, then hand you a report your developers can actually fix.


With hands-on experience in offensive security and cloud environments, I specialize in REST, GraphQL, SOAP, and cloud-native APIs (AWS, Azure, GCP, Kubernetes, Serverless).


What I Test:

  • OWASP API Top 10
  • BOLA / IDOR & Broken Authorization
  • JWT, OAuth2, API Key flaws
  • SQLi, NoSQLi, SSRF, XXE, Command Injection
  • Business Logic & Race Conditions
  • Rate Limiting & DoS resilience
  • Cloud misconfigurations (IAM, S3, Secrets)


What You Get:

  • Executive + Technical PDF report
  • CVSS 3.1-scored findings
  • Proof of Concept for every issue
  • Step-by-step remediation guidance
  • Free retest after fixes
  • NDA signed on request


Why Work With Me:

  • Manual + Automated testing, not scanner dumps
  • Real-world attacker mindset
  • Developer-friendly, no-fluff reports
  • 100% confidential & responsible disclosure


Message me before ordering; every API is different. Let's secure yours before the bad guys find it.

My Portfolio