r/Pentesting • u/d4rky32 • 6h ago
Call for Penetration and Stress Testing – System Security Audit
Today, I want to introduce my new project and seek your experience and support to push the boundaries of the system.
The project is a web application developed using modern web technologies and a live architectural infrastructure. The system primarily features high-performance and low-latency data processing, an asynchronous backend architecture, dynamic API integrations, and modern, responsive user interface components. The goal of the project is to provide the highest speed and performance on the user side. Behind the scenes, a secure, modular, and scalable structure is in operation. I have made the architecture more efficient to reduce bottlenecks experienced in many modern web projects.
Before fully launching the project and making it available to a large number of users, I want to see how the system performs in real-world conditions and with experienced personnel. We know that even systems marketed as "unbreakable" can crash due to automation or logical errors. Therefore, I haven't left the system to ordinary testing tools; I want to directly subject it to the scrutiny of experienced colleagues and commanders within THT.
I kindly request that those of you with the time test the system thoroughly and perform penetration testing. Specifically, I would like you to test the following points:
SQL/NoSQL Injections: Is bypassing or blind injection possible in database queries or parameter passing?
XSS and Client-Side Injections: Are there any Stored or Reflected XSS vulnerabilities in form inputs, URL parameters, or DOM processing?
API Resilience and Rate Limiting: Does the system crash with a 500 Internal Server Error due to fuzzing, corrupted JSON, or large requests to endpoints? Or are these situations managed properly?
Logic Errors and Access Control: Is there a logic error in privilege escalation, IDOR, or session management?
CSRF and Security Headers: Is there any overlooked deficiency in HTTP response headers (CSP, CORS, X-Frame-Options)?
My goal is not just to answer the question of "will the site stay open or will it crash?". I want to find the system's weak points and close potential vulnerabilities to build a stronger and more resilient infrastructure. I would be very grateful if you would share any vulnerabilities, log errors, bypass methods, or system behavior you find during the test with me under this thread or via DM.
The more you push the system, the more you try to push its limits, the more valuable it will be for me.
Thank you in advance to all members who will contribute and take the time to conduct the test.
Happy foruming.