Website Phishing Security Test
Budget / Salary$250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
I want a focused security review of my website aimed at preventing “Cyber attact,” with a particular emphasis on phishing. Your job is to simulate realistic phishing attempts, trace how far an attacker could get, and document every vulnerability you uncover.
Scope of work
• Map the site’s user flows and identify the most attractive phishing entry points.
• Craft and execute controlled phishing scenarios (credential harvesting, fake login pages, social-engineering emails, etc.).
• Record each step, noting where the site does—or does not—block the attack.
• Provide clear, prioritized recommendations to harden the site against future phishing threats.
Deliverables
1. A concise walkthrough of every successful or partially successful phishing vector you discovered.
2. Screenshots or short screen-capture clips that demonstrate exploit steps and resulting system behavior.
3. A remediation checklist ordered by severity and effort required.
The final report should be easy for both developers and non-technical stakeholders to follow. If you have experience with OWASP, penetration-testing frameworks, or automated phishing toolkits, mention it in your bid so I can see how you’ll approach this engagement.
Scope of work
• Map the site’s user flows and identify the most attractive phishing entry points.
• Craft and execute controlled phishing scenarios (credential harvesting, fake login pages, social-engineering emails, etc.).
• Record each step, noting where the site does—or does not—block the attack.
• Provide clear, prioritized recommendations to harden the site against future phishing threats.
Deliverables
1. A concise walkthrough of every successful or partially successful phishing vector you discovered.
2. Screenshots or short screen-capture clips that demonstrate exploit steps and resulting system behavior.
3. A remediation checklist ordered by severity and effort required.
The final report should be easy for both developers and non-technical stakeholders to follow. If you have experience with OWASP, penetration-testing frameworks, or automated phishing toolkits, mention it in your bid so I can see how you’ll approach this engagement.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.