Penetration Testing for Web Application
Budget / Salary$750–1,500
TypeFreelance project
LocationRemote
Posted4 hours ago
Title: Web application Penetration Testing & Security Vulnerability Assessment
Category: Cybersecurity / Web Application Security
Project Overview:
We are looking for an experienced security professional to conduct a penetration test and standard security scan on our web application. The goal is to identify vulnerabilities, misconfigurations, and potential attack vectors before they can be exploited, and to receive a clear, actionable report of findings.
Scope of Work:
Full black-box / grey-box penetration testing of the website (login areas, forms, APIs, user roles, and admin panels where applicable)
Standard automated vulnerability scanning (OWASP Top 10 coverage: SQL injection, XSS, CSRF, broken authentication, insecure direct object references, security misconfigurations, etc.)
Manual testing of business logic and access control (e.g., checking whether one user/account can access another's data)
SSL/TLS configuration review
Server and infrastructure-level security check (open ports, outdated software, exposed services)
Review of session management, authentication, and authorization flows
Deliverables:
A detailed written report listing all vulnerabilities found, categorized by severity (Critical / High / Medium / Low)
Clear reproduction steps for each finding
Recommended fixes/remediation for each issue
A final summary suitable for sharing with non-technical stakeholders
Requirements:
Proven experience in web application penetration testing (please share past reports/certifications if available, e.g., OSCP, CEH, or similar)
Familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, or similar
Ability to sign an NDA before testing begins
Clear, professional written communication in English
Timeline & Budget:
Please share your estimated timeline and cost based on the scope above. Open to both fixed-price and hourly arrangements.
Note: Testing must be conducted in a controlled, non-destructive manner. Any testing that could cause downtime or data loss must be pre-approved before execution.
Category: Cybersecurity / Web Application Security
Project Overview:
We are looking for an experienced security professional to conduct a penetration test and standard security scan on our web application. The goal is to identify vulnerabilities, misconfigurations, and potential attack vectors before they can be exploited, and to receive a clear, actionable report of findings.
Scope of Work:
Full black-box / grey-box penetration testing of the website (login areas, forms, APIs, user roles, and admin panels where applicable)
Standard automated vulnerability scanning (OWASP Top 10 coverage: SQL injection, XSS, CSRF, broken authentication, insecure direct object references, security misconfigurations, etc.)
Manual testing of business logic and access control (e.g., checking whether one user/account can access another's data)
SSL/TLS configuration review
Server and infrastructure-level security check (open ports, outdated software, exposed services)
Review of session management, authentication, and authorization flows
Deliverables:
A detailed written report listing all vulnerabilities found, categorized by severity (Critical / High / Medium / Low)
Clear reproduction steps for each finding
Recommended fixes/remediation for each issue
A final summary suitable for sharing with non-technical stakeholders
Requirements:
Proven experience in web application penetration testing (please share past reports/certifications if available, e.g., OSCP, CEH, or similar)
Familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, or similar
Ability to sign an NDA before testing begins
Clear, professional written communication in English
Timeline & Budget:
Please share your estimated timeline and cost based on the scope above. Open to both fixed-price and hourly arrangements.
Note: Testing must be conducted in a controlled, non-destructive manner. Any testing that could cause downtime or data loss must be pre-approved before execution.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.