Certified Web App Penetration Test

via Freelancer ·

Budget / Salary₹1,500–12,500
TypeFreelance project
LocationRemote
Posted3 hours ago
I’m ready for a full-scale, professional penetration test on my production web application and need a certified ethical hacker to execute it. The objective is crystal clear: show me, with evidence, how an attacker could breach the site, especially around two vital areas—authentication/authorization flows and data security.

Scope
• Black-box or gray-box methodology is acceptable so long as you respect live-traffic limits I will provide.
• Focus your effort on login, role-based access controls, session management, encryption practices, and any data at rest or in transit.
• Social-engineering and network layers are outside this engagement; please stay strictly within the web application boundary.

What I expect as deliverables
1. A brief kickoff plan outlining test phases, tools (Burp Suite, OWASP ZAP, Kali, custom scripts, etc.) and timelines.
2. Daily status notes during active testing so I can track progress without slowing you down.
3. A final report that includes:
– Executive summary in plain English for stakeholders
– Step-by-step reproduction of each finding with PoC screenshots, request/response pairs or videos
– CVSS-based severity ratings and business impact commentary
– Actionable remediation guidance, prioritised
4. A short re-test window once fixes are deployed to confirm vulnerabilities have been closed.

Acceptance criteria
• Every claim must be reproducible on my side with your instructions.
• No service outages; any high-risk test will be cleared with me first.
• Report delivered in PDF and editable format within the agreed timeline.

If you hold an active CEH, OSCP, or similar certification and can start within the next week, let’s lock in the schedule.
web security compliance penetration testing encryption network security certified ethical hacking risk assessment security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.