Web application pentesting
Manual assessment of your application, from its first login to its most sensitive workflows.
Helping businesses identify exploitable vulnerabilities in web, mobile, and API applications before attackers do.
Focused assessments that connect technical weaknesses to the risks your business actually faces.
Manual assessment of your application, from its first login to its most sensitive workflows.
Understand how your APIs behave when requests move outside the intended application flow.
Assess the connections between the mobile client, the device, and the services behind it.
Understand how your application is designed, then test how its workflows could be abused. Logic flaws require context, curiosity, and manual analysis beyond standard scanners.
I’m a cybersecurity professional focused on penetration testing, application security, and independent research. Practical SOC and security monitoring experience informs how I connect technical weaknesses to real operational risk. My approach combines an Applied Mathematics background with Computer Science studies and hands-on web, mobile, and API security work.
I assess web applications, mobile applications, APIs, authentication systems, and business logic to identify vulnerabilities before they become real-world security incidents.
How I approach an assessmentRepresentative engagement scopes. These examples are not verified client engagements or endorsements.
Web application assessment
OWASP Top 10, authorization, authentication, IDOR, business logic, and API security.
Illustrative engagement profile
Example scope for assessing identity and resource-access boundaries.
Illustrative engagement profile
Example scope for reviewing tenant boundaries and sensitive workflows.
Illustrative engagement profile
Example scope spanning client-side behavior and backend permissions.
Illustrative, anonymized scenarios. Severity labels are examples, not validated ratings for actual engagements.
An account-security function could allow failed-login events to be generated for arbitrary users without authentication.
Potential denial of account access through abuse of the legitimate lockout mechanism.
Validate request context, throttle abuse, introduce progressive challenges, and monitor lockout patterns.
Inconsistent resource-level authorization could allow access to protected learning content outside the subscription workflow.
Potential unauthorized access to premium content and loss of subscription revenue.
Enforce authorization on every protected backend resource independently of frontend state.
A generic scenario in which a backend endpoint exposes sensitive database information without appropriate access controls.
Potential exposure of sensitive application or user information.
Require authentication, enforce least-privilege authorization, and minimize returned data.
Bug bounty & security research focused on identifying potential high-impact vulnerabilities in real-world applications.
Investigated a potential Windows client attack chain involving delivery and execution of script-based content that could, under specific circumstances, result in command execution on the victim system.
No accepted Meta bounty report, CVE, public disclosure, or official acknowledgement is currently available. This research is not a verified vulnerability.
Some security research presented here remains private and is intentionally described at a high level until validation or coordinated disclosure is complete.
Illustrative case studies showing how an assessment connects discovery, business impact, and remediation.
Testing is conducted only within explicitly authorized scope, with agreed rules of engagement and controlled exploitation.
Tools support the assessment. Manual analysis, application understanding and business-logic testing drive the most valuable findings.
Clear enough for decision-makers. Detailed enough for the engineers fixing the issue.
If you’re preparing a product launch, handling sensitive customer information, or simply want an independent security assessment, get in touch to discuss the scope.
pentest@wonkrusecurity.online