Web Application VAPT
Customer portals, admin panels and single-page apps tested by hand against OWASP Top 10 and ASVS, with the time spent where automated tools fall short: access control and business logic.
- Broken access control & IDOR
- Payment and workflow logic abuse
- Injection, SSRF & upload handling