Skip to content

Repository files navigation

Web Application Penetration Testing Portfolio

Personal web app pentesting projects — authorized assessments of my own applications, documented end-to-end with professional methodology.

Projects

1. SecureHeaders (header-security-project)

Multi-round assessment of a custom HTTP security headers application.

Round Report Findings
Round 1 pentest_report_header-security-project.md 10 findings
Round 2 pentest_report_v2_header-security-project.md 14 findings
Round 3 (Final) pentest_report_v3_final_header-security-project.md 4 findings (post-remediation)

Key techniques: XSS, SSRF + bypass chains, CORS misconfiguration, CSRF, rate limiting, request smuggling, cache poisoning, prompt injection.

2. ToroHack / RexCTF (torohack-rexctf-com)

CTF-style web application assessment.

Round Report
Round 1 pentest_report_torohack-rexctf-com.md
Round 2 pentest_report_v2_torohack-rexctf-com.md

Authorization Package

All engagements follow a documented authorization framework:

Tools & Resources

See Hacking_Resources_Tools_Practice.md for the full toolkit and practice resources used.


All targets are personal projects. Testing was authorized and conducted ethically.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors