I will be your web application penetration tester and security auditor


About this gig
Are you concerned about hidden vulnerabilities in your web application? I am a professional Cybersecurity Analyst and Web Application Penetration Tester dedicated to uncovering critical structural weaknesses before malicious actors can exploit them.
My approach goes beyond basic automated scanners. I specialize in deep manual analysis, focusing on the OWASP Top 10, complex business logic flaws, API integrity mapping, and mathematical parameter validations.
What You Will Get: Deep Manual Testing: Focused on real-world exploit scenarios.
Comprehensive Security Audit: XSS, SQLi, IDOR, CSRF, Access Control, and misconfigurations.
Actionable Reporting: A publication-grade, detailed PDF/Markdown report with step-by-step reproduction and clear remediation strategies for your developers.
Why Choose Me?
Authorized Bug Bounty Hunter experience on enterprise targets.
Strict adherence to asynchronous, text-based communication-no mandatory video or voice calls required. You get clear, zero-noise, professional results delivered straight to your inbox.
Solid foundation in network security and infrastructure.
Let's fortify your application's backend defense. Order now!
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Ni Zaw
Web Application Penetration Tester and API Security Specialist
- FromMyanmar [Burma]
- Member sinceJul 2026
Languages
English, Russian
FAQ
Do you use automated scanners or manual testing?
I use a hybrid approach, but the core of my service is deep manual testing. Automated tools often miss complex business logic flaws and API vulnerabilities, which are my primary focus.
What do you need from me to start the penetration test?
I need the target URL/scope, test credentials (if authenticated testing is required), and explicit written permission/authorization to perform the security assessment on your assets.
Can we jump on a quick video call to discuss the project?
To maintain maximum efficiency and a clear paper trail, I handle all communication securely via text/chat. You will receive a highly detailed, professional report that clearly outlines everything your development team needs.
Do you write custom automation scripts for security testing?
Yes, absolutely. I frequently develop custom Python scripts tailored to your application's unique architecture. I use these proprietary scripts to fuzz API endpoints, automate logical workflow testing, and simulate specific attack vectors
Can you audit and review Linux backend server configurations?
Yes. Having a strong technical foundation in configuring and managing Linux backend environments, I don't just stop at the web application layer. I analyze server-side configurations, check for privilege escalation vectors, evaluate container security misconfigurations.

