I will perform owasp web application and api penetration test with report


Over deze dienst
Your app is live. Has anyone tried to break in the way a real attacker would?
I am a certified cybersecurity analyst (Security+, SC-900) who performs OWASP-aligned penetration tests on web apps, APIs, and MERN/Next.js stacks not generic scans.
WHAT I TEST
Auth bypass, JWT flaws, session hijacking
SQL/NoSQL injection, XSS, CSRF, SSRF
Broken access control and IDOR on APIs
Misconfigurations, exposed secrets, weak headers
Dependency CVEs and cloud config leaks
AI-coded gaps: hardcoded secrets, missing auth
HOW I WORK
Attack surface mapping and manual exploitation
Tool-assisted scanning with proof-of-concept steps
Severity-rated findings (Critical to Low)
Remediation guidance with code examples
YOU RECEIVE
Penetration test report (PDF)
Executive summary for stakeholders
Re-test on Premium after fixes
IDEAL FOR
Pre-launch startups and funding due diligence
SaaS teams without a security engineer
Agencies needing client security sign-off
NDA available. Send your URL or repo before ordering.
Portfolio: tusherinsight.com
Respecteer de rechten van derden
Let erop dat het tegen het beleid van Fiverr voor freelancers is om thema's, templates of andere elementen in het geleverde werk op te nemen die inbreuk maken op de rechten van derden of toepasselijke wetten. Lees er meer over in onze Gids voor verantwoorde digitale creatie.
Maak kennis met M H Tusher
Cybersecurity Analyst, Web Developer, Security Plus, SC 900
- Afkomstig uitBangladesh
- Lid sindsjan 2024
- Gem. reactietijd1 uur
Talen
Bengaals, Engels
Mijn portfolio
Veelgestelde vragen
Is this a real pentest?
Yes — manual OWASP-aligned testing with documented exploitation attempts and remediation.
Black-box or white-box?
Basic = black-box (URL only). Standard/Premium = white-box with repo or staging access.
Next.js, WordPress, Python?
All common stacks. WordPress-specific malware work is my other gig (GIG-01).
Will you hack without permission?
Only scoped systems you own. Signed rules of engagement on Standard and Premium.
SOC 2 or compliance?
Premium Extra adds auditor-friendly findings summary. Full compliance prep = see my SOC 2 gig.

