I will perform a professional web app pentest test and deliver a full security report

Kenya

I speak English

Cybersecurity Engineer

Penetration tester and ethical hacker, with hands-on experience conducting authorized security assessments against live systems — including a full black-box pentest on a government recruitment portal....
About this Gig

Is your web application truly secure or are you just assuming it is?


Most businesses launch apps and never test them. Attackers do not wait for you to catch up. I find the vulnerabilities before they do, document every finding with proof, and give you a clear roadmap to fix them.


This is not automated scanning renamed as a pentest. This is manual, methodical, adversarial testing performed by a human who understands how attackers think.


My testing methodology follows the OWASP Top 10 and covers:

SQL injection and blind injection variants

Cross-site scripting (XSS) reflected, stored, and DOM-based

Broken authentication and session management flaws

Insecure direct object references (IDOR)

Cross-site request forgery (CSRF) etc...


Every engagement includes a professional PDF report containing:

Executive summary non-technical overview for business stakeholders

Technical findings each vulnerability explained clearly

Severity ratings Critical / High / Medium / Low / Informational

CVSS scores for every finding

Screenshot proof of concept for each vulnerability

OWASP classification for each finding

Step-by-step remediation guidance your dev team can act on immediately

Cloud provider:

Amazon Web Services

Expertise:

Configuration

Other

Cloud computing resource:

Security Groups