Web Application Penetration Testing

via Freelancer ·

Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
I need a thorough penetration test of our customer-facing web application with the clear objective of uncovering every exploitable vulnerability before our next release. The focus is strictly on web application penetration testing, not network, wireless, or broader security audits, and the end goal is an actionable vulnerability report rather than a compliance attestation or IR drill.

Scope
• Black-box and authenticated testing of the entire app (front-end, back-end APIs, third-party integrations).
• Manual exploitation techniques layered on top of automated scanning to reveal business-logic flaws that scanners miss.
• OWASP Top 10 and beyond: injection, broken access control, insecure deserialization, IDORs, privilege escalation, session weaknesses, and any other issues you identify.

Deliverables
1. Executive-level summary highlighting critical findings in plain language.
2. Technical report with detailed vulnerability descriptions, POC screenshots, risk ratings, and reproducible remediation steps.
3. A retest after fixes to confirm closure of all high and critical issues.

Acceptance Criteria
• Every identified vulnerability includes CVSS score and practical mitigation guidance.
• False positives removed; each finding must be reproducible on our staging environment.
• Final report delivered in both PDF and editable format within the agreed timeframe.

You are free to use Burp Suite Pro, ZAP, Kali, or your preferred toolset as long as the methodology aligns with OWASP and PTES best practices. Access credentials to a cloned staging server and API documentation will be provided once the engagement starts.
web security testing / qa software testing usability testing penetration testing technical documentation risk assessment security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.