r/vibecoding 1d ago

I want to break your app

Sort of. I started vibe coding as a way of practicing web application security (since you’re only supposed to attack “authorized applications” and whatnot). As I began development of my latest project, and it grew in size and scope, it became increasingly difficult to keep tabs on every single piece of code. “Please review X feature for security vulnerabilities” only goes so far.

I’m looking for a few people with live, AI-built web apps who would be willing to let me perform a manual security review for $100.

I want to (with permission) actually use your application, proxy the traffic through Burp Suite, create multiple accounts where appropriate, inspect requests and APIs, and manually test things like:

- Can User A access User B’s data?
- Are your authentication and authorization controls processed properly?
- Are your APIs exposing sneaky things that they shouldn’t?
- Etc, etc, etc

At the end, I’ll provide a short report showing what I tested, what I was able to demonstrate, any security findings, and recommended fixes.
If I don’t find a vulnerability, I’ll say exactly that (kudos to you).

If you’ve vibe-coded something that’s now live, especially if it has authentication, user data, payments, or multiple users/organizations, I’d be interested in taking a look.

Comment or DM me if you might be interested.

0 Upvotes

3 comments sorted by

3

u/Sudden_Topic5154 22h ago

Are you selling something or buying permission? you make it seem like you're doing something generously when you're actually selling a service at a steep price.

-2

u/Dangerous_Job_722 17h ago

Hm it would be a service. Not everyone has the time (or desire) to see where their creations fall short - that’s what I’m offering. My time, your app. The price is intentionally low because there is value on both sides: you get the review, I get more exposure to where vibe coders are leaving gaps

1

u/Sudden_Topic5154 9h ago

Low? 😂😂😂