Gray-Box Web App Penetration Test

via Freelancer ·

Budget / Salary$3,000–5,000
TypeFreelance project
LocationRemote
Posted1 hour ago
Our production web application needs a comprehensive gray-box penetration test that evaluates its overall security posture. Source-code access and limited internal documentation will be provided, yet I still expect the perspective of an external attacker.
The assessment must explicitly explore:
• SQL injection vectors
• Cross-site scripting (XSS) risks
• Possibilities for man-in-the-middle attacks on data in transit

Feel free to use your preferred toolkit—Burp Suite, OWASP ZAP, Kali Linux modules, custom scripts—so long as the methods are reproducible.

Deliverables
• A concise executive summary in plain English outlining high-level findings and business impact
• A detailed technical report that maps each finding to OWASP Top 10/CWE, includes proof-of-concept payloads, reproduction steps, screenshots, and suggested remediations
• A retest plan so I can verify fixes internally

The engagement is complete when every critical or high-severity issue is either resolved or has a documented mitigation path that we both agree on.
linux web security computer security mysql penetration testing network security risk assessment security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.