I will perform manual API and graphql security testing with a full report
Security Researcher
À propos de ce service
I test APIs by hand, the way an attacker actually would - not by pointing a scanner at your swagger file.
What I test:
Broken object level authorisation (IDOR) and broken function level authorisation
Mass assignment and parameter tampering
GraphQL introspection, query depth and batching abuse
JWT, session and token handling
Rate limiting and resource exhaustion
Injection and SSRF through API parameters
Business logic you can only break by understanding what the endpoint is for
What you get:
Every finding with a severity rating, exact reproduction steps, a working proof of concept, and a fix your backend team can ship. If a bug isn't real, it isn't in the report.
Why me:
I rank in the top 1% of researchers on HackerOne, with assigned CVEs and security credits from Microsoft MSRC and Google's Open Source VRP.
Before you order:
You must own the API or hold written permission to test it. Message me with your base URL, auth method and anything off limits, and I'll confirm fit and timeline.
Test d'applications:
Application Web
Technologie de développement:
Go
•
JavaScript
•
Node.js
•
PHP
•
Python
Appareil:
PC
•
Mac
•
Linux
FAQ
Will testing break my API or corrupt my data?
No. All testing is manual and non-destructive by default. I don't run automated floods or anything that risks availability. If a check could affect data or uptime, I ask for your explicit approval first, or work against staging instead.
What do you need from me to get started?
The base URL plus a collection or schema if you have one (Postman, OpenAPI or GraphQL), how auth works and two test accounts if roles matter, confirmation you own the API or are authorised to have it tested, and anything out of scope.
Do you test GraphQL as well as REST?
Yes, both are covered in every package. For GraphQL that includes introspection exposure, nested query depth and aliasing abuse, batching attacks and field level authorisation, which is where most GraphQL bugs actually live.
