I will audit your API for broken access control and authorization bugs

Nepal

I speak English, Nepali, Hindi

Security Researcher and Web Security Tester

I am a web security tester focused on identifying real-world vulnerabilities in web applications and APIs using a bug bounty style approach. I specialize in testing for: * Cross-Site Scripting (XSS) ...
About this Gig

Your API might be leaking other users' data right now and standard scanners won't catch it.

I specialize in API authorization testing: IDOR/BOLA, broken object-level access control, mass assignment, and business logic flaws the vulnerability classes that automated tools consistently miss because they require understanding how your app's roles and ownership rules should work, then breaking them.

What you get:

  • Manual, hypothesis-driven testing of your API endpoints (REST/GraphQL)
  • Multi-account testing across roles/tenants to catch horizontal & vertical privilege escalation
  • A clear report: vulnerability, reproduction steps, business impact, and remediation guidance
  • No generic scanner output every finding is manually verified

Good fit for: SaaS platforms, fintech, marketplaces, or any product with user-owned resources and role-based access.

I've found and reported real-world IDOR/BOLA and business logic bugs across multiple bug bounty programs (HackerOne, Bugcrowd, Intigriti). I bring that same hypothesis-first methodology to your assessment.

My Portfolio