I will perform manual API and graphql security testing with a full report

India

I speak English, Hindi

Security Researcher

I am a security researcher in the top 1% on HackerOne and a CSE undergrad. My expertise includes vulnerability research for Google and Microsoft, where I hunt for gaps between documentation and code e...
About this Gig

I test APIs by hand, the way an attacker actually would - not by pointing a scanner at your swagger file.


What I test:

Broken object level authorisation (IDOR) and broken function level authorisation

Mass assignment and parameter tampering

GraphQL introspection, query depth and batching abuse

JWT, session and token handling

Rate limiting and resource exhaustion

Injection and SSRF through API parameters

Business logic you can only break by understanding what the endpoint is for


What you get:

Every finding with a severity rating, exact reproduction steps, a working proof of concept, and a fix your backend team can ship. If a bug isn't real, it isn't in the report.


Why me:

I rank in the top 1% of researchers on HackerOne, with assigned CVEs and security credits from Microsoft MSRC and Google's Open Source VRP.


Before you order:

You must own the API or hold written permission to test it. Message me with your base URL, auth method and anything off limits, and I'll confirm fit and timeline.

Testing application:

Web application

Development technology:

Go

•

JavaScript

•

Node.js

•

PHP

•

Python

Device:

PC

•

Mac

•

Linux