I will perform API security testing and vulnerability assessment
Protecting Websites and Networks with Practical Cyber Solutions
About this Gig
Is your REST or GraphQL API exposing data or allowing unauthorized access?
I test it manually not just a scanner and find real exploitable issues.
I hold the API Security Fundamentals certification and have tested APIs professionally at SNSKIES across web applications and NDR systems.
What I Test (OWASP API Top 10):
· Broken Object Level Authorization (BOLA/IDOR)
· Broken Authentication JWT flaws, token handling
· Excessive Data Exposure
· Rate limiting bypass and resource exhaustion
· SQL/command injection via API parameters
· Mass assignment vulnerabilities
· Security misconfigurations
· GraphQL introspection and query abuse
Tools: Burp Suite · Postman · FFUF · SQLmap · custom Python scripts
Deliverable: Professional PDF findings, CVSS ratings, PoC evidence, fix guidance.
Share API docs or Swagger spec before ordering.
Device:
Desktop
•
Laptop
•
Server
Operating system:
Windows
•
Linux
•
Ubuntu
My Portfolio
FAQ
Do you need API documentation to start?
Helpful but not required. I can enumerate endpoints manually. A Swagger/Postman collection speeds up the process.
What's the difference between Basic and Standard?
Basic uses automated scanning. Standard is manual.I actively exploit BOLA, JWT flaws, mass assignment, and business logic issues that scanners miss entirely
Can you test authenticated APIs?
Yes. Provide test credentials or API keys. I work within agreed scope only.
Do you test GraphQL?
Yes , introspection checks, query complexity attacks, field-level authorization testing. Mention GraphQL when ordering.

