Harden Social Media Web App
Budget / Salary$10–30
TypeFreelance project
LocationRemote
Posted1 hour ago
I need a seasoned vulnerability researcher to comb through my social-media-style web application and surface every exploitable path to Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF). The codebase is a typical React front-end served by a Node/Express API with a MongoDB backend, all containerised in Docker and running behind Nginx.
Scope
The engagement covers the full production replica: unauthenticated, authenticated, and privilege-escalation flows, including upload modules, messaging, profile edits, and any third-party integrations. Only web vectors are in scope; mobile clients and network infrastructure scanning are out of scope for now.
Methodology
Feel free to bring your own toolkit—Burp Suite Pro, OWASP ZAP, custom scripts, browser dev-tools extensions—so long as findings are reproducible. I will supply you with test accounts, API keys, source maps, and a staging URL.
Deliverables
• A concise report for each verified XSS or CSRF issue, detailing:
– Step-by-step reproduction (with screenshots or PoC scripts)
– Impact assessment (data theft, account takeover, etc.)
– Recommended remediation or patch code snippet
• A final executive summary ranking all issues by criticality (OWASP severity scale).
• Optional follow-up retest once fixes are deployed (counted as a separate milestone).
Acceptance Criteria
A deliverable is accepted when the provided PoC reliably triggers on the current staging build, the write-up is clear enough for my devs to reproduce, and the remediation advice is technically sound.
Timeline
Initial findings expected within one week of access; complete report within two.
If this fits your skillset, let’s get you into the environment and start breaking things—before the bad actors do.
Scope
The engagement covers the full production replica: unauthenticated, authenticated, and privilege-escalation flows, including upload modules, messaging, profile edits, and any third-party integrations. Only web vectors are in scope; mobile clients and network infrastructure scanning are out of scope for now.
Methodology
Feel free to bring your own toolkit—Burp Suite Pro, OWASP ZAP, custom scripts, browser dev-tools extensions—so long as findings are reproducible. I will supply you with test accounts, API keys, source maps, and a staging URL.
Deliverables
• A concise report for each verified XSS or CSRF issue, detailing:
– Step-by-step reproduction (with screenshots or PoC scripts)
– Impact assessment (data theft, account takeover, etc.)
– Recommended remediation or patch code snippet
• A final executive summary ranking all issues by criticality (OWASP severity scale).
• Optional follow-up retest once fixes are deployed (counted as a separate milestone).
Acceptance Criteria
A deliverable is accepted when the provided PoC reliably triggers on the current staging build, the write-up is clear enough for my devs to reproduce, and the remediation advice is technically sound.
Timeline
Initial findings expected within one week of access; complete report within two.
If this fits your skillset, let’s get you into the environment and start breaking things—before the bad actors do.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.