
Henok Habte
Addis Ababa, Ethiopia
Henok Habte
IDOR/BOLA Security Specialist
Category : Cybersecurity
I am a web application security specialist with a deep focus on Broken Access Control vulnerabilities, specifically IDOR (Insecure Direct Object Reference) and BOLA (Broken Object Level Authorization) – the #1 risk in the OWASP API Security Top 10 .
Automated scanners are great for finding known vulnerabilities, but they completely fail to find logic flaws like IDORs. That's where I come in. I manually test your web application or API to find these critical holes before a bad actor does.
My Offer: A Focused Security Assessment for $250
Here’s what you get:
2-3 Hours of Manual Testing: I will thoroughly test your authentication, authorization, and key user flows.
A Clear, Professional Report: You'll receive a PDF report detailing each finding, including:
Title & Severity: (e.g., "Critical IDOR in User Profile API")
Proof of Concept: Step-by-step instructions with screenshots showing exactly how to reproduce the vulnerability .
Business Impact: A clear explanation of the real-world risk (e.g., "An attacker could steal all customer PII").
Remediation Guide: Simple, actionable steps your developer can take to fix the issue immediately .
48-Hour Turnaround: You get your results fast.
My Guarantee: If I find zero critical or high-severity vulnerabilities, you pay nothing. This is a no-risk way to secure your application.
I have extensive experience hunting for IDORs on platforms like HackerOne and understand how attackers think. Let me help you secure your project.
Automated scanners are great for finding known vulnerabilities, but they completely fail to find logic flaws like IDORs. That's where I come in. I manually test your web application or API to find these critical holes before a bad actor does.
My Offer: A Focused Security Assessment for $250
Here’s what you get:
2-3 Hours of Manual Testing: I will thoroughly test your authentication, authorization, and key user flows.
A Clear, Professional Report: You'll receive a PDF report detailing each finding, including:
Title & Severity: (e.g., "Critical IDOR in User Profile API")
Proof of Concept: Step-by-step instructions with screenshots showing exactly how to reproduce the vulnerability .
Business Impact: A clear explanation of the real-world risk (e.g., "An attacker could steal all customer PII").
Remediation Guide: Simple, actionable steps your developer can take to fix the issue immediately .
48-Hour Turnaround: You get your results fast.
My Guarantee: If I find zero critical or high-severity vulnerabilities, you pay nothing. This is a no-risk way to secure your application.
I have extensive experience hunting for IDORs on platforms like HackerOne and understand how attackers think. Let me help you secure your project.
Portfolio
Working hours
- Monday:08h00 To 18h00
- Tuesday:08h00 To 18h00
- Wednesday:08h00 To 18h00
- Thursday:08h00 To 18h00
- Friday:08h00 To 18h00
- Saturday:Not available
- Sunday:Not available
- 🇬🇧 English
Please sign in as a customer to give your feedback






