I will perform manual API and graphql security testing with a full report

Alcune informazioni sono riportate in lingua inglese.

India

Parlo Inglese, Hindi

Security Researcher

I am a security researcher in the top 1% on HackerOne and a CSE undergrad. My expertise includes vulnerability research for Google and Microsoft, where I hunt for gaps between documentation and code e...
Informazioni su questo servizio

I test APIs by hand, the way an attacker actually would - not by pointing a scanner at your swagger file.


What I test:

Broken object level authorisation (IDOR) and broken function level authorisation

Mass assignment and parameter tampering

GraphQL introspection, query depth and batching abuse

JWT, session and token handling

Rate limiting and resource exhaustion

Injection and SSRF through API parameters

Business logic you can only break by understanding what the endpoint is for


What you get:

Every finding with a severity rating, exact reproduction steps, a working proof of concept, and a fix your backend team can ship. If a bug isn't real, it isn't in the report.


Why me:

I rank in the top 1% of researchers on HackerOne, with assigned CVEs and security credits from Microsoft MSRC and Google's Open Source VRP.


Before you order:

You must own the API or hold written permission to test it. Message me with your base URL, auth method and anything off limits, and I'll confirm fit and timeline.

Applicazione di testing:

Applicazione web

Tecnologia di sviluppo:

Go

•

JavaScript

•

Node.js

•

PHP

•

Python

Dispositivo:

PC

•

Mac

•

Linux