I will do website and web application penetration testing and vulnerability assessment


À propos de ce service
I help businesses find and fix security vulnerabilities in their websites and web applications before attackers do through structured, OWASP Top 10-aligned penetration testing.
WHAT YOU GET
- Manual + automated testing of your website/web app against the OWASP Top 10
- A clear, prioritized report: Critical / High / Medium / Low severity
- Practical remediation steps for every finding (not just a vulnerability dump)
- A short call to walk through the results if you need it
WHY WORK WITH ME
I hold dual EC-Council CEH v13-aligned certifications (Advanced Red Teaming Practitioner + SOC Analyst Operations) and built SentinelScan, a live OWASP Top 10 / MITRE ATT&CK-aligned scanning platform I engineered end-to-end. I also completed a full authorized external penetration test on a live production domain (banoqabil.pk) with a formal PDF remediation report; this isn't theoretical- it's applied.
WHAT'S NOT INCLUDED: Physical security testing, social engineering/phishing simulations, DDoS testing, and production network infrastructure pentesting are outside the scope for this gig message me if you need a custom quote for those.
Respectez les droits des tiers
Veuillez noter qu’il est contraire aux politiques de Fiverr pour les freelances d’inclure des thèmes, des modèles ou tout autre élément d'autrui qui enfreint les droits de tiers ou les lois applicables pour les livrables. En savoir plus en lisant notre Guide pour une création numérique responsable.
Découvrez Daniyal Rashid
Web App Penetration Tester, OWASP Top 10, Vulnerability Assessment, CEH v13
- DePakistan
- Membre depuisaoût 2026
Langues
Anglais
Mon portfolio
FAQ
Do you need login access to my site?
Only for authenticated testing in the Standard/Premium package (e.g., testing behind a login). Basic scans don't require credentials.
Will testing cause downtime or break anything?
I test carefully to avoid disruption, but any live security testing carries a small inherent risk. I recommend testing on staging where possible, and I'll flag anything destructive before running it.
Do I need to give you written authorization?
Yes, you must confirm that you own the domain or have explicit written permission to have it tested. This is required before I start any work (to protect both of us).
What's actually in the report?
Every vulnerability found, its severity (Critical/High/Medium/Low), how it could be exploited, and specific steps to fix it, not just a raw scanner output.
Can you test a staging environment instead of production?
Yes, and it's usually the safer option to send the staging URL in your order requirements.
What if my site is behind a firewall/WAF that blocks scanning?
Let me know the requirements, and I'll send you IPs to whitelist so the scan isn't blocked.

