Comprehensive Web Application and API Penetration TestingComprehensive Web Application and API Penetration Testing
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Comprehensive web application penetration test, API endpoint analysis, and vulnerability assessment for a production-facing infrastructure ecosystem.
The Objective: An enterprise client required a full-scope security assessment to evaluate their external attack surface, verify strict alignment with the OWASP Application Security Verification Standard (ASVS Level 3), and uncover critical server-side and business logic flaws before deploying a major code release.
The Approach: I executed a hybrid security assessment combining automated reconnaissance with deep manual exploitation across the application layer and its integrated APIs. Every vulnerability was manually validated using Burp Suite Professional, SQLmap, and Postman to eliminate false positives and scored using standard CVSS 3.1 metrics.
From a single comprehensive audit, I uncovered 24 reproducible findings:
2 High Severity: Broken Object Level Authorization (BOLA/IDOR) on critical billing endpoints and a SQL injection flaw in the primary authentication pathway.
5 Medium Severity: Faulty session management allowing session fixation, missing Rate Limiting on public API routes, and Cross-Site Scripting (XSS) via un-sanitized comment inputs.
7 Low Severity: Lax CORS configuration rules, missing secure flag attributes on cookies, and verbose server error disclosures.
10 Informational: Exposure of outdated software banners and missing HTTP security headers (such as Content-Security-Policy).
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started