Web Application Security Assessment
Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted1 hour ago
I need an experienced ethical hacker to carry out a thorough penetration test against my live web application. Your task is to approach the site exactly as an outside attacker would, probe every publicly reachable endpoint, and uncover any weakness that could put user data or business logic at risk.
Scope
• Only the web layer is in scope—no mobile clients or internal network segments.
• Testing should cover common OWASP Top 10 vectors as well as business-logic flaws unique to the app.
• You may use the tools you are most comfortable with (Burp Suite, OWASP ZAP, Nmap, custom scripts, etc.) as long as you respect the production environment and avoid service disruption.
Deliverables
• A clearly structured report detailing each finding, its risk rating, reproduction steps, and practical remediation advice.
• Proof-of-concept screenshots or requests demonstrating successful exploitation where applicable.
• A concise executive summary suitable for non-technical stakeholders.
Acceptance Criteria
The engagement is complete when every confirmed vulnerability is documented with enough detail for my development team to reproduce and fix it, and no critical or high-risk issue remains unreported.
If you have recent experience auditing modern web stacks and can begin soon, I’d like to hear about your methodology and timeline.
Scope
• Only the web layer is in scope—no mobile clients or internal network segments.
• Testing should cover common OWASP Top 10 vectors as well as business-logic flaws unique to the app.
• You may use the tools you are most comfortable with (Burp Suite, OWASP ZAP, Nmap, custom scripts, etc.) as long as you respect the production environment and avoid service disruption.
Deliverables
• A clearly structured report detailing each finding, its risk rating, reproduction steps, and practical remediation advice.
• Proof-of-concept screenshots or requests demonstrating successful exploitation where applicable.
• A concise executive summary suitable for non-technical stakeholders.
Acceptance Criteria
The engagement is complete when every confirmed vulnerability is documented with enough detail for my development team to reproduce and fix it, and no critical or high-risk issue remains unreported.
If you have recent experience auditing modern web stacks and can begin soon, I’d like to hear about your methodology and timeline.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.