Mac88 Penetration Security Audit
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted6 hours ago
I’ve just finished the latest build of the Mac88 website and need an experienced tester to perform a thorough penetration test with security as the sole focus. The goal is to probe both network security and the application layer, uncovering real-world attack vectors that could compromise data, interrupt service, or damage user trust.
Scope
• Simulate external and internal attacks against the live environment.
• Examine common application flaws (OWASP Top 10) and misconfigurations.
• Map and exploit network-level weaknesses such as open ports, unsecured services, and privilege-escalation paths.
• Stress-test user-facing components to identify injection points, insecure session handling, and authentication bypasses.
I’m comfortable with industry-standard tooling—Burp Suite, OWASP ZAP, Nmap, Metasploit, Wireshark, etc.—so feel free to choose the stack that lets you work fastest and deepest.
Deliverables
1. Executive summary for non-technical stakeholders.
2. Detailed technical report listing each vulnerability, risk rating, proof-of-concept, and step-by-step remediation guidance.
3. Retest verification once fixes are applied.
Please outline your approach, the approximate timeline, and any prerequisites you’ll need from me (e.g., staging credentials, IP whitelisting). I’m ready to kick things off as soon as you are.
Scope
• Simulate external and internal attacks against the live environment.
• Examine common application flaws (OWASP Top 10) and misconfigurations.
• Map and exploit network-level weaknesses such as open ports, unsecured services, and privilege-escalation paths.
• Stress-test user-facing components to identify injection points, insecure session handling, and authentication bypasses.
I’m comfortable with industry-standard tooling—Burp Suite, OWASP ZAP, Nmap, Metasploit, Wireshark, etc.—so feel free to choose the stack that lets you work fastest and deepest.
Deliverables
1. Executive summary for non-technical stakeholders.
2. Detailed technical report listing each vulnerability, risk rating, proof-of-concept, and step-by-step remediation guidance.
3. Retest verification once fixes are applied.
Please outline your approach, the approximate timeline, and any prerequisites you’ll need from me (e.g., staging credentials, IP whitelisting). I’m ready to kick things off as soon as you are.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.