Web application pentesting
Testing modern web applications, auth flows, and business logic for exploitable weaknesses including XSS, IDOR, SQLi, SSRF, access-control flaws, token abuse, and chained impact.
Hands-on web application penetration testing across modern apps, APIs, auth flows, and business logic. Currently preparing for HTB Certified Web Exploitation Specialist (CWES).
My focus is practical assessment work: finding exploitable weaknesses in web applications and APIs, then translating the technical path into clear business risk, remediation, and report-ready evidence.
Testing modern web applications, auth flows, and business logic for exploitable weaknesses including XSS, IDOR, SQLi, SSRF, access-control flaws, token abuse, and chained impact.
Hunting real-world web targets for XSS, IDOR, auth bypass, business-logic flaws, and chained impact — with clear reproduction steps and report-ready evidence.
Testing REST/GraphQL APIs, session handling, JWT and OAuth flows, access-control gaps, mass assignment, and other auth/session abuse paths.
Mapping exposed services, misconfigurations, credential paths, weak permissions, and privilege escalation opportunities into clear attack chains and practical remediation.
I work as a web penetration tester. The focus is understanding how applications fail in the real world: where authentication breaks, how trust gets abused, how small misconfigurations become attack paths, and how findings chain into real impact.
My work is centered on web application pentesting, bug bounty hunting, API security, internal assessments, automation, and professional reporting. I use Python to automate workflows, test attack ideas quickly, and turn repeatable findings into methodology.
A sharper view of the work: web application and API assessment skills, bug bounty methodology, internal paths, and client-ready reporting. HTB CWES track.
Web App Pentesting, Bug Bounty Hunter, API Security, Internal Assessments
XSS, SQLi, SSRF, IDOR, Auth Bypass, File Inclusion, Command Injection, API & GraphQL Attacks
Recon, Threat Modeling, Exploitation, Impact Proof, Remediation, Client-Ready Reporting
Burp Suite, Caido, Nmap, ffuf, SQLMap, Metasploit, Wireshark, Python, Bash, Docker
Python, Rust, JavaScript, Bash, Docker, Linux