Unauthorized access to credit-card customer PII.
Sensitive information associated with credit-card customers could be retrieved outside the intended access controls.
Business impact: customer data exposureWeb + API VAPT
Manual testing across authorization, authentication, APIs and business logic. Findings are reported in terms of what an attacker could actually access, change or control.
Security work
Sensitive information associated with credit-card customers could be retrieved outside the intended access controls.
Business impact: customer data exposureThe issue affected a high-value identity account flow and was later fixed.
Business impact: account compromiseAn authorization flaw allowed privilege escalation to administrator-level access.
NVD ↗Vendor advisory ↗Validated findings included database injection, persistent/reflected script injection, and a broken account-update authorization control that weakened the intended 2FA boundary.
Technical detail: SQL injection · stored/reflected XSS · broken authorizationThe assessment identified a cross-tenant authorization failure in a multi-tenant security platform.
Business impact: tenant-isolation failureBackground
Security Engineer / Penetration Tester at BugBase. Web & API assessments, exploitability analysis, vulnerability triage and remediation validation.
TryHackMe Road ↗ · Intigriti 1337UP Traveller challenge · 20 Docker-based security labs for PWNX.
1st place — Great AppSec Hackathon 2026 · 2nd individual — Ghost in the Ledger, IIT Bombay.
Python and Bash automation for testing helpers, repetitive security workflows and edge-case reproduction.
CRTP + CWES — practical offensive-security certifications.
Independent VAPT
I scope the engagement, perform the testing, write the report and retest the fixes myself. No sales-to-tester handoff.
Lower overhead keeps the fee lean — not the testing depth.
Start with the scope
Application type, user roles, API scope and preferred testing window are enough to start. I’ll reply with scope questions, timeline and a fixed quote.
jalajkumar1011@gmail.com ↗