I will perform manual API and graphql security testing with a full report

Parte de la información aparece en idioma inglés.

India

Hablo Inglés, Hindi

Security Researcher

I am a security researcher in the top 1% on HackerOne and a CSE undergrad. My expertise includes vulnerability research for Google and Microsoft, where I hunt for gaps between documentation and code e...
Acerca de este Servicio

I test APIs by hand, the way an attacker actually would - not by pointing a scanner at your swagger file.


What I test:

Broken object level authorisation (IDOR) and broken function level authorisation

Mass assignment and parameter tampering

GraphQL introspection, query depth and batching abuse

JWT, session and token handling

Rate limiting and resource exhaustion

Injection and SSRF through API parameters

Business logic you can only break by understanding what the endpoint is for


What you get:

Every finding with a severity rating, exact reproduction steps, a working proof of concept, and a fix your backend team can ship. If a bug isn't real, it isn't in the report.


Why me:

I rank in the top 1% of researchers on HackerOne, with assigned CVEs and security credits from Microsoft MSRC and Google's Open Source VRP.


Before you order:

You must own the API or hold written permission to test it. Message me with your base URL, auth method and anything off limits, and I'll confirm fit and timeline.

Aplicación de prueba:

Aplicación web

Tecnología de desarrollo:

Go

•

JavaScript

•

Node.js

•

PHP

•

Python

Dispositivo:

PC

•

Mac

•

Linux