Comprehensive Security Check for my Platform

via Freelancer ·

Budget / Salary₹600–1,500
TypeFreelance project
LocationRemote
Posted2 hours ago
Security Audit and Penetration Testing for Web and Mobile Application

Project Overview

I am looking for an experienced security auditor and penetration tester to perform a comprehensive security audit of a web application and mobile application.

The application handles sensitive user and platform data through a backend database. The main objective of this project is to identify security vulnerabilities and, most importantly, verify that unauthorized users cannot access data or functionality that they are not permitted to access.

The primary focus is on backend authorization, API security, database access control, authentication, privilege escalation, and protection against unauthorized data access.

Main Security Requirement

I need to verify that a normal user cannot access another user’s private or restricted information by manipulating API requests, IDs, parameters, requests, or other application components.

For example:

* User A must not be able to access User B’s private information.
* User A must not be able to access User B’s products or records.
* User A must not be able to access User B’s chats or messages.
* User A must not be able to access User B’s rental or transaction information.
* User A must not be able to access restricted KYC or sensitive information.
* User A must not be able to modify or delete User B’s information.
* A normal user must not be able to access administrator functionality.
* A normal user must not be able to change their role or privileges.
* Unauthenticated users must not be able to access protected APIs.

The security controls must be enforced on the backend/server side and should not rely only on frontend restrictions.

Scope of Testing

1. Web Application Security

Test the complete web application, including:

* Authentication and login
* Registration
* User profiles
* Product listing and management
* Product browsing
* Rental functionality
* Transactions and payments
* Chat and messaging
* KYC functionality
* Notifications
* Search
* User-specific data
* Administrative functionality
* Authenticated APIs
* Unauthenticated APIs
* Backend-connected functionality

2. Mobile Application Security

Perform security testing of the mobile application, including the underlying APIs and backend services.

The testing should not be limited to the mobile interface. The APIs should be manually tested to determine whether requests can be modified to access unauthorized information or functionality.

3. API Security

Test the APIs for:

* Broken authentication
* Broken authorization
* IDOR
* BOLA
* Privilege escalation
* Authentication bypass
* Authorization bypass
* Parameter tampering
* Request manipulation
* Mass assignment
* Excessive data exposure
* Missing authorization checks
* HTTP method manipulation
* Sensitive information exposure
* Improper error handling
* Exposed internal endpoints
* Debug or test endpoints
* Unprotected APIs
* Excessive permissions

4. Access Control Testing

Test different user roles and verify that access restrictions are correctly implemented.

At minimum, test:

* Unauthenticated user
* Normal User A
* Normal User B
* Administrator

Verify that users can only access resources and perform actions that they are authorized to access.

5. Database and Backend Security

Assess whether unauthorized users can directly or indirectly access database information through the application’s APIs or backend.

Check for:

* Exposed database credentials
* Public database access
* Unauthorized database records returned through APIs
* Missing backend authorization
* Access to other users’ records
* Unauthorized modification of records
* Unauthorized deletion of records
* Excessive backend permissions
* Exposed sensitive information
* Insecure service-account permissions

6. Cloud and Server Security

If the application uses AWS, Firebase, or other cloud services, review relevant security configurations.

Check for:

* Publicly accessible databases
* Public storage
* Exposed credentials
* Over-permissioned IAM roles
* Incorrect security group configuration
* Unnecessary open ports
* Exposed environment variables
* Exposed API keys or secrets
* Insecure database security rules
* Insecure storage permissions
* Publicly accessible backend services

7. Mobile Application Security

Where applicable, check for:

* Hardcoded credentials or secrets
* Exposed API keys
* Insecure local storage
* Sensitive information stored insecurely
* API authentication weaknesses
* Certificate/transport security issues
* Client-side security controls that can be bypassed
* Reverse engineering risks
* Unauthorized API access through modified requests

Expected Deliverables

I expect a professional security audit report containing:

1. Executive Summary

Overall assessment of the application’s security condition.

2. Vulnerability Report

For each vulnerability:

* Vulnerability name
* Severity: Critical, High, Medium, Low, or Informational
* Affected application
* Affected endpoint/component
* Description
* Security impact
* Steps to reproduce
* Evidence/screenshots where appropriate
* Recommended fix
* Verification method

3. Authorization Matrix

Provide a clear matrix showing which user roles can access important resources and functionality.

4. API Security Assessment

List important APIs tested and whether proper authentication and authorization are enforced.

5. Database Access Assessment

Clearly state whether a normal user can access unauthorized database information directly or indirectly through the application.

6. Remediation Recommendations

Provide practical recommendations that developers can use to fix the identified issues.

7. Retesting

After vulnerabilities are fixed, a retest may be required to confirm that the vulnerabilities have been properly resolved.

Important Requirements

I am not looking for someone who only runs an automated vulnerability scanner and provides a generic report.

The project requires manual security testing in addition to automated tools.

The freelancer should have strong experience with:

* OWASP Top 10
* OWASP API Security Top 10
* IDOR and BOLA
* Broken Access Control
* RBAC
* API penetration testing
* Web application penetration testing
* Mobile application security testing
* Cloud security
* Database security
* Privilege escalation

Testing Restrictions

Testing should preferably be performed in a staging or testing environment.

I will provide appropriate test accounts and access.

No destructive testing, data deletion, payment manipulation, production database modification, or other potentially disruptive activity should be performed without explicit approval.

The freelancer must not copy, retain, disclose, or use sensitive application data obtained during the security assessment for any purpose outside this project.

Proposal Requirements

Please include:

1. Your experience with web and mobile penetration testing.
2. Examples of similar security audits you have completed.
3. Your experience identifying IDOR/BOLA and privilege-escalation vulnerabilities.
4. Whether your testing includes manual testing.
5. Your proposed testing methodology.
6. Estimated timeline.
7. Fixed price or estimated hours.
8. Tools you intend to use.
9. Whether a security retest is included after remediation.

Success Criteria

The project should establish whether:

* Unauthorized users can access restricted backend data.
* Users can access another user’s private information.
* APIs properly enforce authorization.
* Administrative functionality is protected.
* Database access is properly restricted.
* Authentication and authorization bypasses are possible.
* Sensitive information is exposed through APIs or application components.
* Cloud and server permissions are appropriately configured.

The primary objective is to ensure that sensitive application and database information cannot be accessed or manipulated by unauthorized users through the web application, mobile application, APIs, backend services, or cloud infrastructure.
penetration testing cloud security certified ethical hacking security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.