I will perform web application penetration testing owasp top 10
Junior Penetration Tester
About this Gig
Looking for a thorough, manual web application security assessment? You're in the right place.
I'm a Penetration Tester and Bug Bounty Hunter with verified, real-world findings on government and enterprise targets:
NASA Hall of Fame P2 vulnerability accepted on nasa.gov
Zebra VDP 2026 Hall of Fame Rank #4 on HackerOne
DoD VDP accepted reports
What I test:
- OWASP Top 10 (Injection, Broken Auth, IDOR, XSS, CSRF, SSRF, etc.)
- Business logic flaws & access control issues
- REST & GraphQL API security
- Authentication & session management
What you get:
- Professional report with CVSS severity scoring
- Clear proof-of-concept for each finding
- Actionable remediation recommendations
- 1-on-1 debrief on findings
Tools: Burp Suite, SQLmap, Nmap, Nikto, custom scripts
Certifications: eJPT | CRTA | CRTOM | Certified API Security Analyst
️ Important: I only test applications you own or have written authorization to test. Please message me before ordering to confirm scope.
Let's secure your application together!
My Portfolio
FAQ
Do you need access/credentials to test?
Yes, please provide test account credentials and the target URL after ordering so I can begin testing efficiently.
Is written authorization required?
Yes. Please confirm in writing (message) that you own this application or have permission to test it before placing your order.
Do you test mobile apps?
Currently I focus on web applications and REST/GraphQL APIs. Mobile app testing is not included in this gig.
What if you find critical vulnerabilities?
I'll flag critical findings immediately during testing, even before the final report, so you can start remediation early.
