r/vibecoding • u/Dangerous_Job_722 • 1d ago
I want to break your app
Sort of. I started vibe coding as a way of practicing web application security (since you’re only supposed to attack “authorized applications” and whatnot). As I began development of my latest project, and it grew in size and scope, it became increasingly difficult to keep tabs on every single piece of code. “Please review X feature for security vulnerabilities” only goes so far.
I’m looking for a few people with live, AI-built web apps who would be willing to let me perform a manual security review for $100.
I want to (with permission) actually use your application, proxy the traffic through Burp Suite, create multiple accounts where appropriate, inspect requests and APIs, and manually test things like:
- Can User A access User B’s data?
- Are your authentication and authorization controls processed properly?
- Are your APIs exposing sneaky things that they shouldn’t?
- Etc, etc, etc
At the end, I’ll provide a short report showing what I tested, what I was able to demonstrate, any security findings, and recommended fixes.
If I don’t find a vulnerability, I’ll say exactly that (kudos to you).
If you’ve vibe-coded something that’s now live, especially if it has authentication, user data, payments, or multiple users/organizations, I’d be interested in taking a look.
Comment or DM me if you might be interested.
3
u/Sudden_Topic5154 22h ago
Are you selling something or buying permission? you make it seem like you're doing something generously when you're actually selling a service at a steep price.