I will perform a web application penetration test
Pentester, Offensive Security Researcher
About this Gig
Get a real, manual penetration test of your website not just an automated scan. I test login security, XSS, IDOR, and more, then deliver a clear report with practical fixes.
My Portfolio
FAQ
What do you need from me before the test?
Please provide the target URL, testing scope, any required credentials (if applicable), and written authorization to perform the security assessment. I only test systems that you own or are authorized to test.
What types of vulnerabilities do you test for?
I perform manual and automated testing based on industry best practices, including the OWASP Web Security Testing Guide and OWASP Top 10. Common issues include SQL Injection, Cross-Site Scripting (XSS), Broken Access Control, IDOR, SSRF, CSRF, Authentication flaws, File Upload vulnerabilities, Secur
Will my application be damaged during testing?
No. The assessment is performed in a controlled and responsible manner. I avoid destructive testing and aim to minimize any impact on production environments. If you have a staging environment available, I recommend testing there whenever possible.
What will I receive after the assessment?
You will receive a professional penetration testing report that includes: Executive Summary Scope and Methodology Technical Findings CVSS Severity Ratings Proof of Concept (when applicable) Risk Assessment Detailed Remediation Recommendations
What's your experience/background?
eJPT-certified Penetration Tester and member of one of Brazil's top-ranked Hack The Box teams, with hands-on experience in HTB ProLabs, real-world security assessments, and daily offensive security research.

