Full Web Security Audit & OWASP ASVS Compliance (27 Findings)
Comprehensive web application penetration test and vulnerability assessment for a production hosting infrastructure.
A production hosting provider required a full-scope security audit to evaluate their attack surface, verify compliance with the OWASP Application Security Verification Standard (ASVS Level 2), and uncover critical business-logic vulnerabilities before public deployment.
I executed a hybrid security assessment combining automated reconnaissance with deep manual exploitation using Burp Suite. Every vulnerability was manually validated to eliminate false positives and scored using standard CVSS 3.1 metrics.
From a single comprehensive audit, I uncovered 27 reproducible findings:
2 High Severity: Exposed database backups and critical Cross-Site Scripting (XSS) execution vectors.
8 Medium Severity: CORS misconfigurations, XML-RPC brute-force paths, and authentication bypass vectors.
10 Low Severity: Unrestricted directory listings and insecure header configurations.
7 Informational: Information disclosure and software version leaks.
Starting from zero is uncomfortable. But sometimes, it’s exactly what you need to build the next chapter.
I’m new to Contra. But I’m definitely not new to cybersecurity.
A few years ago, I started taking on security and automation projects on Upwork.
Since then, I’ve worked with clients on real technical problems from vulnerability discovery and web security testing to Python automation and QA.
That journey taught me something important:
Clients don’t just need someone who can find a vulnerability.
They need someone who can understand it, validate it, explain the risk, and help fix it.
I’m now bringing that same mindset to Contra.
Here’s what I help with:
🔐 Web Application Penetration Testing
🔐 API Security Testing
🔍 Vulnerability Assessment
🛡️ Security Testing & Retesting
🐍 Python Security Automation
🧪 QA / SQA & Test Automation
I’m proud to have built a 5-star track record on Upwork, but starting on a new platform means starting from zero again.
And honestly?
I’m okay with that.
Because the platform is new to me
the work isn’t.
This is a new chapter for SCOLTECH, and I’m looking forward to connecting with founders, developers, startups, and businesses that care about building secure software.
If you’re building a web application or API and want to know where your security weaknesses are before someone else finds them let’s talk.
New on Contra.
Same standards.
Same commitment to quality.