I will perform a professional rest or graphql API security penetration test

Pakistan

I speak English, Hindi, Urdu

Penetration Tester OSCP CPTS Certified

OSCP & CPTS certified penetration tester at Privacy Ninja (professional VAPT firm). I perform manual web app, API & WordPress security assessments — not scanner output. WHAT YOU GET: - OWASP Top 10 &...
About this Gig

yet most go untested. I am an OSCP & CPTS certified penetration tester specializing in API security. I manually test your REST or GraphQL API against the OWASP API Security Top 10.


WHAT I TEST:

  • BOLA/IDOR: accessing other users' resources
  • - Broken Authentication: weak tokens, JWT issues, API key exposure
  • - Broken Function Level Authorization: admin endpoints accessible to users
  • - Unrestricted Resource Consumption: rate limiting, resource exhaustion
  • - SSRF via API parameters
  • - Security Misconfiguration: verbose errors, debug endpoints, CORS
  • - Injection: SQL, NoSQL, command injection via API parameters
  • - OData Injection in enterprise/Microsoft APIs

  • DELIVERABLES:
  • - Professional PDF VAPT report
  • - CVSS scores per finding
  • - PoC requests (cURL/Postman) for every vulnerability
  • - Remediation guidance
  • - Re-test included (Standard & Premium)

  • NDA available. Testing is non-destructive.APIs are the most targeted attack surface in modern apps

Related tags