I will perform web application penetration testing and security assessment


About this gig
Are you worried about hackers exploiting your website or mobile app?
Hold on. You've come to the right place!
As a cybersecurity professional, Faheem specialize in web application penetration testing and security assessment using the same methodology I've used for real clients like AttoLearn. I find vulnerabilities before attackers do.
What I Offer:
- Web Application Penetration Testing
- OSINT Reconnaissance (Shodan, HIBP, AbuseIPDB, Whois, DNS Checker)
- Nessus Vulnerability Scanning
- MobSF Mobile App Static Analysis
- API Security Testing (IDOR, Auth Bypass, Endpoint Enumeration)
- Cloudflare WAF Bypass & Origin Server Exposure Testing
- IIS / ARR Misconfiguration Analysis
- Detailed Report with Evidence, Risk Ratings & Remediation
Why Hire Me?
- Real-world pentesting experience
- Industry-standard tools & methodology
- Clear, actionable reports with screenshots
- Milestone-based delivery
- Free support after delivery
Your security is one click away. Message me now, and let's make your application hacker-proof.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Faheem Shahid
Cybersecurity Engineer, Agentic Security
- FromPakistan
- Member sinceJan 2023
- Avg. response time1 hour
Languages
English
My Portfolio
FAQ
What do I need to provide for the security assessment?
Just your website URL or mobile app APK. I will handle the rest — recon, scanning, testing, and reporting.
Will my website or app be damaged during testing?
No. I follow a safe, controlled testing methodology. All tests are performed with caution to avoid any service disruption.
What kind of vulnerabilities do you check for?
OWASP Top 10 including IDOR, authentication bypass, information disclosure, SQL injection, API endpoint exposure, origin server bypass, and server misconfigurations.
What will I receive after the assessment?
A detailed security report with executive summary, screenshots, risk ratings (Critical/High/Medium/Low), raw evidence, and step-by-step remediation instructions.
Which tools do you use?
MCP-Kali-Server (Nmap, curl, dig), Nessus, MobSF, Shodan, HIBP, AbuseIPDB, DomainDNS Checker, Whois, and browser DevTools.

