Penetration Test: Web & Network
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
I need a thorough security assessment of both our public-facing web applications and the underlying network infrastructure. For the web layer, your testing must zero-in on two critical areas—Authentication & Authorization and Input Validation—so we can be confident that user identities are protected and no injection or validation bypass is possible. On the network side, I’m looking for the classic internal and external penetration workflow: reconnaissance, vulnerability discovery, exploitation, and clear remediation guidance.
Deliverables
• Executive summary that highlights overall posture and business risk
• Technical report detailing:
– Findings for Authentication & Authorization
– Findings for Input Validation
– Network vulnerabilities with proof-of-concept evidence
• Re-test memo confirming fixes (one follow-up round included)
Acceptable testing tools include Burp Suite, Nmap, Metasploit, or similar; feel free to bring your own proven toolkit as long as it produces reproducible results. All activities must respect ethical hacking standards and be scheduled during our approved maintenance windows.
If you can kick off within a week and deliver the initial report in two, let’s talk.
Deliverables
• Executive summary that highlights overall posture and business risk
• Technical report detailing:
– Findings for Authentication & Authorization
– Findings for Input Validation
– Network vulnerabilities with proof-of-concept evidence
• Re-test memo confirming fixes (one follow-up round included)
Acceptable testing tools include Burp Suite, Nmap, Metasploit, or similar; feel free to bring your own proven toolkit as long as it produces reproducible results. All activities must respect ethical hacking standards and be scheduled during our approved maintenance windows.
If you can kick off within a week and deliver the initial report in two, let’s talk.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.