I will manually pentest for owasp top 10 vulnerabilities


About this gig
I'm from Red Team. I don't make noise or stress using automated tools blindly.
I provide manual web penetration testing to identify vulnerabilities that automated tools often miss and false positive. With hands-on skills from HackTheBox , Portswigger & TryHackMe, I will test your website like a real attacker carefully and safely without making too much unnecessary traffics.
#Here is exactly what I will manually test on your web application:
- Broken Access Control (IDOR, privilege escalation)
- Cryptographic Failures (weak encryption, exposed secrets)
- Injection Flaws (SQLi, NoSQLi, Command Injection)
- Insecure Design (business logic bypasses)
- Security Misconfigurations (default credentials, exposed admin panels)
- Vulnerable & Outdated Components (checking your libraries for CVEs)
- Identification & Authentication Failures (session hijacking, brute-force logic)
- Software & Data Integrity Failures (CI/CD pipeline flaws)
- Security Logging & Monitoring Failures (verifying if you would even notice an attack)
- Server-Side Request Forgery (SSRF)
You will receive a professional report containing POC, DETAIL BREAKDOWN, RETEST AFTER FIX if required (FOR AN EXTRA GIG).
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Shuvo Dutta
Web Security expert with 3years of experience
- FromBangladesh
- Member sinceNov 2024
- Avg. response time1 hour
- Last delivery2 weeks
Languages
Bengali, English
My Portfolio
FAQ
Will testing affect my site availability?
I avoid destructive techniques. Manual testing is low-impact, but some checks (e.g., logic testing) might change application state. I’ll perform safe tests by default and coordinate timing if you need strict uptime guarantees.
How do you handle sensitive data you find?
I follow strict confidentiality. I’ll not exfiltrate or store real user data unnecessarily. All sensitive findings are handled securely and removed from reports on request after remediation.
Which tools do you use?
I rely mostly on manual techniques and selective tooling (browser devtools, Burp Suite, proxy tools, custom scripts) to validate findings. I avoid noisy mass-scanners unless requested.
How do you price the engagement?
Pricing depends on scope (# of pages/endpoints, auth flows, API complexity). See my packages for typical scopes.
What information do I get before you start?
Pre-engagement checklist: scope, rules of engagement, authorized IPs, preferred testing window, and access credentials.

