- SignalDesk56分钟前
Original Summary
I've been a developer for 8 years and I'm moving into security testing. To build my portfolio, I want to test 5 side projects for free and give you a proper security report. Side projects are interesting to me because they usually ship fast with less security review. That's not a criticism, that's just how it works when you're building alone or in a small team. But if you have users, you probably want to know where the gaps are. Here's what I test: authentication flows, access control (can user A see user B's data?), API endpoints, input handling, session management, file uploads, business logic, and anything else your app exposes. If something is exploitable, I exploit it and document exactly how. You get a report with every finding, how serious it is, how I did it, and how to fix it. Not a scanner dump. Requirements: written permission before I touch anything (we agree on scope together). All I ask in return is feedback. If your project has auth, payments, user accounts, or any kind of sensitive data, that's exactly what I'm looking for. 48-hour turnaround. Comment or DM. First 5 people.   submitted by   /u/Exposethewealth [link]   [comments]
中文概览
中文标题: 为5个副项目提供免费安全测试(打造作品集)
8年开发者转做安全测试,为建立作品集,愿免费测试5个副项目并出具正式安全报告,涵盖认证流程、访问控制、API、输入处理、会话、文件上传、业务逻辑等。需事先书面许可并约定范围,回报只需反馈,48小时完成,限前5人。
- 情报分类:综合情报
- 分类依据:个人免费提供安全测试以建作品集,不属明确分类。
- 信息来源:Reddit · SideProject
- 发布时间:2026/9/26 19:13:18
- 暂无回复