Email & CCTV Penetration Testing vulnerability check
Budget / SalaryA$250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
Our internal security policy calls for a fresh look at two critical assets: the company email platform and the IP-based surveillance camera network.
For the email system I need a full-scale engagement that combines vulnerability assessment with active penetration testing. Map the attack surface, exploit any weakness you discover, and document step-by-step how you achieved it. I rely on this to verify patch levels, credential handling, SPF/DMARC efficacy, and potential lateral-movement paths, so depth matters more than speed.
The camera side is limited to a network security assessment. Focus on what can be reached or manipulated over the wire—open ports, firmware exposure, weak encryption, default credentials, VLAN or VPN segregation issues, traffic interception, and anything else an attacker might leverage without physical access.
Please conduct all testing during an agreed maintenance window and provide:
• A concise executive summary for management
• A detailed technical report with evidence, CVSS scores, and practical remediation steps
• Proof-of-concept scripts or captures where exploitation was successful
All findings must be reproducible. Common toolsets such as Nmap, Nessus, Metasploit, Wireshark, Burp Suite, or your preferred equivalents are fine as long as you note versions used.
For the email system I need a full-scale engagement that combines vulnerability assessment with active penetration testing. Map the attack surface, exploit any weakness you discover, and document step-by-step how you achieved it. I rely on this to verify patch levels, credential handling, SPF/DMARC efficacy, and potential lateral-movement paths, so depth matters more than speed.
The camera side is limited to a network security assessment. Focus on what can be reached or manipulated over the wire—open ports, firmware exposure, weak encryption, default credentials, VLAN or VPN segregation issues, traffic interception, and anything else an attacker might leverage without physical access.
Please conduct all testing during an agreed maintenance window and provide:
• A concise executive summary for management
• A detailed technical report with evidence, CVSS scores, and practical remediation steps
• Proof-of-concept scripts or captures where exploitation was successful
All findings must be reproducible. Common toolsets such as Nmap, Nessus, Metasploit, Wireshark, Burp Suite, or your preferred equivalents are fine as long as you note versions used.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.