Personal web app pentesting projects — authorized assessments of my own applications, documented end-to-end with professional methodology.
Multi-round assessment of a custom HTTP security headers application.
| Round | Report | Findings |
|---|---|---|
| Round 1 | pentest_report_header-security-project.md | 10 findings |
| Round 2 | pentest_report_v2_header-security-project.md | 14 findings |
| Round 3 (Final) | pentest_report_v3_final_header-security-project.md | 4 findings (post-remediation) |
Key techniques: XSS, SSRF + bypass chains, CORS misconfiguration, CSRF, rate limiting, request smuggling, cache poisoning, prompt injection.
CTF-style web application assessment.
| Round | Report |
|---|---|
| Round 1 | pentest_report_torohack-rexctf-com.md |
| Round 2 | pentest_report_v2_torohack-rexctf-com.md |
All engagements follow a documented authorization framework:
- Scope of Work
- Rules of Engagement
- Emergency Contacts & Notification
- Test Timeline
- NDA / Confidentiality Agreement
- Quick Reference Card
See Hacking_Resources_Tools_Practice.md for the full toolkit and practice resources used.
All targets are personal projects. Testing was authorized and conducted ethically.