Student Portal Penetration Test
Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted1 hour ago
I have just tightened the security around our university database and want to prove the new controls really work. A dummy student account is already in place and an internal approval letter from our IT department clears this exercise as an authorised test.
Your mission is to log in strictly with student-level credentials, then attempt to:
• alter any academic grades on the dummy record
• modify the tuition-fee balance
While doing so, please try every student-side route you can think of—including techniques that may slip past both our firewalls and our intrusion-detection system. The moment you manage to trigger a change (or if you are blocked), document every action, tool, and payload you used, noting timestamps so I can match them against the staff-portal logs.
Deliverables I need:
1. A step-by-step report detailing each attempt, whether successful or not, and the exact vector employed.
2. Proof of any visible data change on the student portal and confirmation of whether it propagated to the staff portal. Screenshots or screen recordings are ideal.
3. A concise vulnerability summary ranked by severity, plus clear remediation advice.
This is a focused, single-account penetration test; no production data will be touched. If that sounds feasible, let me know what additional information or access details you require and how long you anticipate the engagement will take.
Your mission is to log in strictly with student-level credentials, then attempt to:
• alter any academic grades on the dummy record
• modify the tuition-fee balance
While doing so, please try every student-side route you can think of—including techniques that may slip past both our firewalls and our intrusion-detection system. The moment you manage to trigger a change (or if you are blocked), document every action, tool, and payload you used, noting timestamps so I can match them against the staff-portal logs.
Deliverables I need:
1. A step-by-step report detailing each attempt, whether successful or not, and the exact vector employed.
2. Proof of any visible data change on the student portal and confirmation of whether it propagated to the staff portal. Screenshots or screen recordings are ideal.
3. A concise vulnerability summary ranked by severity, plus clear remediation advice.
This is a focused, single-account penetration test; no production data will be touched. If that sounds feasible, let me know what additional information or access details you require and how long you anticipate the engagement will take.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.