Executed comprehensive web application VAPT, including OWASP Top 10 and SANS Top 25 testing. Discovered critical access control flaws, insecure session handling, and misconfigured security headers, significantly improving the application's security posture.
MOBILE APPLICATION VAPT
Mobile Application VAPT
Conducted end-to-end mobile application VAPT covering authentication, authorization, insecure storage, reverse engineering, root/jailbreak bypass, and API abuse. Mapped findings against OWASP MASVS and OWASP Mobile Top 10, resulting in critical risk remediation before production release.
API SECURITY ASSESSMENT
API Security Assessment
Performed deep API security testing, including IDOR, privilege escalation, mass assignment, and business logic abuse on microfinance APIs. Identified high-impact authorization flaws affecting fund transfer and beneficiary management workflows.
BUG BOUNTY & DISCLOSURE
Bug Bounty & Responsible Disclosure
Actively participated in private and public bug bounty programs. Reported multiple valid security issues through responsible disclosure channels, focusing on access control, data exposure, and authentication weaknesses.
SECURITY HARDENING
Security Hardening
Reviewed and validated application configurations against security best practices, including TLS hardening, secure headers, and access controls. Ensured alignment with organizational and regulatory security requirements.