
Closed
Posted
Paid on delivery
I’m looking for a security professional to carry out a full-scale penetration test on our production mobile app, targeting both iOS and Android builds. Because this assessment is mobile-specific, I need you to zero in on three critical areas: • Authentication – verify that login, session management and any social/SSO flows can’t be bypassed or abused. • Data storage security – confirm that sensitive information is never left exposed in local storage, keychains, logs or backups. • API integrations – probe every call the app makes to our back-end, ensuring proper authorization, rate-limiting and input validation. I’ll provide the latest IPA and APK, test accounts, and high-level architecture docs. Your job is to emulate realistic attacker behavior, using standard toolsets such as OWASP Mobile Testing Guide techniques, Burp Suite, Frida or similar, and to keep meticulous notes for evidence. Deliverables: 1. Executive summary in plain language for management. 2. Detailed technical report mapping each finding to CVSS/CWE, proof-of-concept steps, reproducible screenshots or videos, and clear remediation advice. 3. Clean retest confirmation once fixes are applied. All testing must respect responsible disclosure and be performed within the agreed window. Let me know your estimated timeline and any prerequisites you need before kickoff.
Project ID: 40558023
35 proposals
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
35 freelancers are bidding on average ₹100,195 INR for this job

I can help with this, I will test both your iOS and Android builds across all three areas you outlined: authentication and SSO bypass attempts, local data storage exposure (keychain, logs, backups), and every API call for authorization gaps and input validation flaws. The thing most mobile pentests miss is the runtime layer. I will use Frida to hook into the running app and test session handling, certificate pinning, and token storage under real attacker conditions, not just static analysis. That approach is what surfaces the findings that matter. You will get the executive summary, the full technical report with CVSS/CWE mapping and reproducible PoCs, and the retest confirmation after remediation. Looking forward to talking through the details. Kamran
₹84,404 INR in 25 days
7.4
7.4

Hi, I have experience performing mobile application security assessments for both Android and iOS, following the OWASP Mobile Testing Guide and industry best practices. I can thoroughly evaluate authentication, session management, local data storage, and API security using tools such as Burp Suite, Frida, MobSF, and other standard security testing frameworks. You'll receive a comprehensive executive summary, a detailed technical report with CVSS/CWE mappings, proof-of-concept evidence, remediation recommendations, and a complete retest after fixes are implemented. I can begin immediately after receiving the APK, IPA, test accounts, and architecture documentation. I look forward to discussing your testing scope and timeline.
₹150,000 INR in 7 days
7.2
7.2

Hello, I’m an experienced Cybersecurity and Penetration Testing professional with extensive experience in mobile application security assessments for both Android and iOS. I can perform a comprehensive VAPT of your APK and IPA, focusing on authentication, session management, secure local data storage, API security, and OWASP Mobile Top 10 risks using tools such as Burp Suite, Frida, MobSF, JADX, and OWASP MASTG methodologies. You'll receive a professional executive summary, a detailed technical report with CVSS/CWE mappings, proof-of-concept evidence, remediation recommendations, and a complete retest validation after fixes are implemented. I maintain clear documentation throughout the engagement and strictly follow responsible disclosure practices. I'm available to start immediately and can complete the assessment within the agreed timeline once I receive the APK/IPA, test accounts, and supporting documentation. Looking forward to working with you. Regards
₹120,000 INR in 7 days
5.3
5.3

Hello, I am Penetration tester with 10 years of experience in mobiles apps , servers and web applications. both applications are listed on appstore and playstore? i would take 12 days including report. i need app functionality document as well.
₹112,500 INR in 12 days
5.4
5.4

Hello, I'm Rudra Kumar, a highly experienced and versatile QA/DevOps engineer who can bring your mobile app penetration testing project to new heights of security. With over 7 years in the field, I've honed my skills in Manual Testing, Automation Testing, Performance Testing, Security Testing and DevOps - all of which are crucial for the success of your project. My expertise includes mobile app testing for both iOS and Android builds, so you can be confident in my ability to fully assess your application's security. What sets me apart is my complete dedication to quality throughout the entire software development cycle. I am proficient in applying various test methodologies and checking every aspect crucial to your project such as authentication, data storage security, and API integrations. Using cutting-edge tools like OWASP Mobile Testing Guide techniques, Burp Suite, Frida, along with traditional ones like JMeter, Postman etc., I emulate real-world attacker behavior ensuring no stone is left unturned. I possess an analytical mindset that helps me dissect every finding from the assessment accurately mapping each one to CVSS/CWE along with detailed proof-of-concept steps and clear remediation advice.
₹100,000 INR in 30 days
4.8
4.8

As an accomplished and seasoned technology professional with a profound background specifically in mobile app development and AI-driven solutions, I understand the pressing need for robust security measures to safeguard users' sensitive data. Over the past two decades, I have applied my technical prowess to design and develop complex mobile applications with secure data storage, multi-factor authentication, and tightly-integrated API systems. My proficiency also extends to penetration testing, making me the ideal candidate to scrutinize your production mobile app. With my extensive experience in utilizing OWASP Mobile Testing Guide techniques, Burp Suite, Frida, and other relevant tools, I can efficiently emulate realistic security threats. Additionally, my understanding of CVSS/CWE vulnerability ratings will ensure that I provide you with a comprehensive and detailed technical report mapping each finding along with clear remediation advice. With unauthorized access being a major risk in mobile apps, your login, session management, and social/SSO flows are in safe hands with me. I have always placed responsible disclosure as a top priority in my work akin to adhering to agreed-upon schedules. Rest assured that I will flawlessly apply this approach while bridging the weak points in your app's backend.
₹75,000 INR in 7 days
4.4
4.4

I understand that you need a comprehensive security assessment of your production mobile applications with a strong emphasis on authentication, local data protection, and backend API security. The objective is not only to identify vulnerabilities but to validate the application's resilience against realistic attack scenarios and provide clear remediation guidance. My approach is to perform a structured assessment following the OWASP Mobile Testing Guide, combining static and dynamic analysis, API security testing, runtime instrumentation, and secure storage validation across both Android and iOS. The final deliverables will include an executive summary, detailed technical findings with proof of concept, prioritized remediation recommendations, and a complete verification report confirming that all identified critical issues have been successfully resolved.
₹112,500 INR in 30 days
4.4
4.4

Interesting project, We will perform a full penetration test on your iOS and Android builds, covering authentication flows, local data storage, and every API endpoint the app calls. Our approach starts with dynamic instrumentation using Frida to hook into runtime methods and inspect token handling, keychain entries, and certificate pinning. This reveals issues static analysis misses, such as session tokens persisting after logout or sensitive data leaking into device backups. A couple of quick things to confirm: 1) Does the app use certificate pinning, and should we test bypass scenarios? 2) Are there any third-party SDKs (analytics, crash reporting) we should include in scope? The number quoted here is a starting estimate. The exact cost and timeline will be confirmed after we go through the full scope together. Looking forward to your response. Best regards, Faizan
₹83,150 INR in 25 days
4.1
4.1

Hi, I'm Karthik, a Full-Stack Developer with 15+ years of experience building secure enterprise and mobile applications, with hands-on experience in application security reviews, API security, and penetration testing aligned with OWASP Mobile Testing Guide and OWASP Top 10. I can perform a comprehensive security assessment of your iOS and Android applications, focusing on: ✔ Authentication & session management (including SSO/social login) ✔ Secure local data storage (Keychain/Keystore, Shared Preferences, SQLite, logs & backups) ✔ API security testing (authorization, rate limiting, input validation, token handling) ✔ Traffic interception and runtime analysis using Burp Suite, Frida, MobSF, and OWASP methodologies ✔ Business logic and common mobile attack vector assessment Deliverables: ✔ Executive summary for stakeholders ✔ Detailed technical report with CVSS/CWE mapping, evidence, PoCs, screenshots, and remediation guidance ✔ Retest verification report after fixes are implemented I follow responsible disclosure practices and maintain complete confidentiality throughout the engagement. Estimated Timeline: 5–7 business days (depending on application complexity). I'd be happy to discuss your testing scope, architecture, and prerequisites to ensure a thorough and efficient assessment. Looking forward to collaborating! – Karthik
₹149,500 INR in 7 days
3.1
3.1

Drawing from my extensive experience in mobile app development and the exhaustive array of services offered by Web Crest, I am confident that I possess all the skills needed to excel at this project. Specifically, my proficiency in Android app development will ensure comprehensive testing for both iOS and Android builds. Apart from this, I have a deep understanding of security parameters necessary for mobile apps, especially regarding Authentication, Data Storage Security, and API Integrations - making me tailor-made for this gig. I'm well-versed with powerful tools like OWASP Mobile Testing Guide techniques, Burp Suite and Frida which will assist in carrying out a thorough penetration test and documenting each step with precision. Additionally, my company's commitment to result-oriented work has always delivered tangible success. Your executive team can expect an executive summary in plain language, a detailed technical report outlining every finding mapped to applicable CVSS/CWE along with clear remediation advice. Finally, what sets us apart is our dedication to long-term technical support and open communication. I will never just disappear after delivering the reports; instead, I'll be there for any retesting or queries you may have even after the project completes.
₹150,000 INR in 7 days
2.8
2.8

Hi, I've reviewed your requirements and understand you're looking for a production-grade mobile penetration test, not an automated vulnerability scan. The assessment will follow the OWASP Mobile Application Security Testing Guide (MASTG) and focus on realistic attack scenarios across Android and iOS. Assessment Scope Authentication & session management (including token validation and bypass attempts) Secure local storage (Keychain/Keystore, Shared Preferences, SQLite, logs, backups) API security (authorization, IDOR, rate limiting, input validation, token handling) Runtime security checks (certificate pinning, root/jailbreak detection where applicable) Deliverables Executive summary for stakeholders Detailed technical report with CVSS, CWE mapping, PoC, evidence, and remediation Retest after fixes to verify remediation Before kickoff, I'll need: IPA/APK builds, test accounts, and API documentation (or Postman collection). Confirmation whether certificate pinning or jailbreak/root detection is currently enabled. I follow a milestone-based approach and request payment only after you've reviewed and approved each deliverable. Thanks Virander
₹135,000 INR in 38 days
2.1
2.1

Hi, I can perform a comprehensive penetration test for your iOS and Android apps following the OWASP Mobile Testing Guide. I'll assess authentication, session handling, local data storage, API security, and business logic using tools like Burp Suite, Frida, and MobSF. You'll receive a detailed CVSS/CWE-based report, proof-of-concepts, remediation guidance, and a retest after fixes to ensure all issues are resolved.
₹91,500 INR in 7 days
1.4
1.4

Hi I have worked on similar portfolio websites and can build this cleanly. I understand you want a minimalist site where your work is the main focus, with no distractions and fast performance across all devices. I’ll build a simple structure (Home, Portfolio, About, Contact) and keep it flexible so you can easily add or rearrange projects later. The design will stay lightweight, responsive, and focused on readability and spacing. For content management, I can set it up either in WordPress or a lightweight static system depending on what you prefer for updates. Everything will be optimized for speed, mobile usability, and clean UI. Let me know: • WordPress for easy editing or static setup for maximum performance?
₹112,500 INR in 7 days
1.0
1.0

Hello, Security testing is essential before scaling a production mobile application. I can perform a comprehensive penetration test of your iOS and Android apps following the OWASP Mobile Application Security Testing Guide (MASTG) and industry best practices, with clear, actionable reporting for both technical and non-technical stakeholders. ### Scope of Assessment ✅ Authentication & Session Management * Login & registration flows * Token/session validation * Social/SSO authentication review * Authorization & privilege escalation testing ✅ Data Storage Security * Local storage inspection * Keychain/Keystore validation * Sensitive data leakage checks * Backup & log analysis ✅ API Security Testing * Authentication & authorization * IDOR/BOLA testing * Input validation * Rate limiting * Business logic assessment * Transport security (HTTPS/TLS) ### Methodology • OWASP MASTG & Mobile Top 10 • Burp Suite Professional • Frida • MobSF • JADX / apktool • Postman & API validation tools I'd be happy to review your IPA, APK, test accounts, and architecture documentation, then finalize the testing schedule and scope before kickoff.
₹112,500 INR in 7 days
4.3
4.3

As an experienced web developer who also has skills in API testing and mobile app development, I bring a unique combination of expertise to ensure the utmost security for your mobile app. Not only do I have a deep understanding of OWASP Mobile Testing Guide techniques, but I'm also proficient in tools like Burp Suite and Frida that are crucial for comprehensive penetration testing on iOS and Android builds. In line with your requirements, my work ethics always revolve around meticulousness, responsible disclosure, and tight deadlines. Having built and tested various web apps, I am thorough in probing authentication processes, data storage security, and API integrations to guarantee every base is covered. Lastly, my experience in critical documentation ensures that you will receive an executive summary that your management can easily digest while there will be no lack of technical details for you. My technical reports are known for mapping findings to CVSS/CWE with clear proof-of-concept steps along with supporting visuals like screenshots or videos. Rest assured, any necessary remediation advice will be given in an actionable manner. For me, the job isn't done until we've come full-circle with a clean retest confirmation once fixes are applied. Let's discuss further and get started on making your mobile app as secure as it can be!
₹75,000 INR in 10 days
0.4
0.4

❤️❤️❤️Hi, I respect your benefit and do my best!❤️❤️❤️ ⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐⭐ ✔ Comprehensive mobile app penetration testing to identify vulnerabilities in authentication, data storage security, and API integrations ✔ Utilizing OWASP Mobile Testing Guide techniques, Burp Suite, Frida, and other standard toolsets to emulate realistic attacker behavior ✔ Detailed technical report with CVSS/CWE mapping, proof-of-concept steps, reproducible screenshots or videos, and clear remediation advice ✔ Clean retest confirmation once fixes are applied ✔ Executive summary in plain language for management ✔ Meticulous notes for evidence and responsible disclosure I'm confident in my ability to deliver a thorough and actionable report that will help you strengthen your mobile app's security posture. Do you have any specific requirements for the testing environment or tools used? Best regards.
₹112,500 INR in 7 days
0.0
0.0

With my name being Geetam, a top-rated freelancer in web and mobile app development for over 5 years; I have the breadth and depth of skills you need to completely secure your mobile app. Having built numerous applications from scratch, my knowledge extends to both iOS and Android platforms. This puts me in a unique position to understand the intricacies of your system while testing its resilience against potential threats. Zeroing in on the critical areas identified, my expertise allows me to fully comprehend and apply tools like OWASP Mobile Testing Guide techniques, Burp Suite, Frida, and similar, for a comprehensive penetration test focused on authentication, data storage security, and API integrations. My reports have always been concise yet detailed enough to allow swift remediation of vulnerabilities found. Additionally, as a dedicated manager of projects involving confidential data in the past, I fully grasp the importance of responsible disclosure and guarantee I'll adhere strictly to it throughout this entire project. To sum it up; there's nothing more satisfying than bringing an aspect of security and robustness that protects both users and the business itself. Engage me today and let me put my skills to work for you in delivering exemplary results that will go way beyond securing your app!
₹85,000 INR in 7 days
0.0
0.0

Hi, I specialize in penetration testing and security assessments for mobile applications with a focus on iOS and Android platforms. While I am early in my freelancing journey, I have a strong understanding of security practices, including authentication, APIs, and data storage security. My approach will align with industry standards like OWASP Mobile Testing Guide and tools such as Burp Suite and Frida. I will deliver: - A detailed executive summary for management. - A comprehensive technical report mapping findings to CVSS/CWE with step-by-step POCs and remediation steps. - Validation of security fixes during retest. Let’s connect to finalize timelines and prerequisites. I am fully dedicated to ensuring that your app is secure against potential exploits! Best regards, Anike
₹112,500 INR in 5 days
0.0
0.0

★★★★★★★★★★★★★★ Dear Respect Client ★★★★★★★★★★★★★ Hi, My name is ⭐Pavlo⭐. I can start your mobile app penetration testing right now and review both iOS and Android builds with OWASP MSTG, Burp Suite, Frida, and API security testing. Will you provide a dedicated test environment or should all authentication, local storage, and API abuse tests be performed only during a fixed production testing window? I will deliver clear CVSS/CWE reports, evidence, remediation steps, and retest confirmation. Best regards.
₹120,000 INR in 15 days
0.0
0.0

As an accomplished mobile app developer with over 5+ years of extensive experience, your penetration testing project piques my interest. I am well-versed in a range of programming languages extending to tools like OWASP Mobile Testing Guide techniques and Burp Suite, which are vital for this precise task. My skills in React JS, Node JS, MongoDB, MySQL, and SQL Server align spot-on with the requirements of ensuring authentication robustness, data storage security, and secure API integrations. What truly distinguishes me from other candidates is my track record of building over 50+ dynamic web applications and comprehensive experience across various tech tools. I have a meticulous eye for detail which would be invaluable for keeping your required detailed notes and mapping findings precisely, proof-of-concept steps, clear suggestions, etc. Furthermore, my past work demonstrates a commitment to upholding the highest coding standards while navigating any vulnerabilities successfully. Best, Akif F
₹75,000 INR in 2 days
0.0
0.0

New Delhi, India
Member since Jul 3, 2026
$10-30 USD
₹12500-37500 INR
$30-250 USD
₹600-1500 INR
₹750-1250 INR / hour
$25-50 USD / hour
₹5000-7000 INR
₹750-1250 INR / hour
$10-30 USD
$30-250 USD
₹600-1500 INR
$3000-5000 USD
$30-250 USD
₹400-750 INR / hour
€1500-3000 EUR
₹1500-12500 INR
$250-750 USD
$15-25 USD / hour
$250-750 USD
$30-250 USD