This is almost as foolish as it is illegal.
Finding web security issues is much more complicated legally than finding security issues in desktop/server software. I can download and install Apache and test it on my local box and discover things like the Range Header DoS. There are no legal issues for me to worry about.
I can't download and install "LinkedIn" and test it for web issues. I have to test against their site running on their computers. Immediately in the US the Computer Fraud and Abuse Act comes into play (though the OP lives in Denmark). "Hmmm, let me 'test' random website X for something that could cause a DoS" is insane.
Even if a company has a formal "we are OK and authorize people to test our site for security issues" policy that is still extremely dangerous from a legal perspective. Maybe you are only authorized if you follow their specific disclosure policies. Maybe you are only authorized to do non-destructive testing. Every company is going to have some tipping point where, if you testing impacts X or caused Y downtime, that's enough damage where they will seek your prosecution.
Building a "security portfolio" against websites is a stupid idea with some potentially huge negative consequences. If anyone insists on doing this, at least go looking for issues in projects that you can download and audit locally.