
Open
Posted
•
Ends in 6 days
Paid on delivery
Title: Web application Penetration Testing & Security Vulnerability Assessment Category: Cybersecurity / Web Application Security Project Overview: We are looking for an experienced security professional to conduct a penetration test and standard security scan on our web application. The goal is to identify vulnerabilities, misconfigurations, and potential attack vectors before they can be exploited, and to receive a clear, actionable report of findings. Scope of Work: Full black-box / grey-box penetration testing of the website (login areas, forms, APIs, user roles, and admin panels where applicable) Standard automated vulnerability scanning (OWASP Top 10 coverage: SQL injection, XSS, CSRF, broken authentication, insecure direct object references, security misconfigurations, etc.) Manual testing of business logic and access control (e.g., checking whether one user/account can access another's data) SSL/TLS configuration review Server and infrastructure-level security check (open ports, outdated software, exposed services) Review of session management, authentication, and authorization flows Deliverables: A detailed written report listing all vulnerabilities found, categorized by severity (Critical / High / Medium / Low) Clear reproduction steps for each finding Recommended fixes/remediation for each issue A final summary suitable for sharing with non-technical stakeholders Requirements: Proven experience in web application penetration testing (please share past reports/certifications if available, e.g., OSCP, CEH, or similar) Familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, or similar Ability to sign an NDA before testing begins Clear, professional written communication in English Timeline & Budget: Please share your estimated timeline and cost based on the scope above. Open to both fixed-price and hourly arrangements. Note: Testing must be conducted in a controlled, non-destructive manner. Any testing that could cause downtime or data loss must be pre-approved before execution.
Project ID: 40629187
48 proposals
Open for bidding
Remote project
Active 13 mins ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
48 freelancers are bidding on average $1,081 USD for this job

Hello, I'd approach this in three phases: automated scanning across OWASP Top 10 categories using Burp Suite, OWASP ZAP, and Nmap; manual testing of authentication, session management, and access control (specifically checking for IDOR and broken authorization between user accounts); and a server/infrastructure review covering SSL/TLS config, open ports, and outdated services. All testing would be non-destructive, with anything higher-risk flagged and pre-approved by you first. Deliverables: a severity-ranked report (Critical/High/Medium/Low) with reproduction steps and remediation guidance for each finding, plus a plain-language summary for non-technical stakeholders. Happy to sign an NDA and share certifications/sample reports on request. Once you confirm scope (user roles, API count, staging vs. production), I can provide a firm timeline and quote.
$1,500 USD in 7 days
7.4
7.4

Hi, I specialize in end-to-end web app, API, and infrastructure testing with nearly a decade of QA and security experience. I will conduct a thorough black-box/grey-box audit using Burp Suite and OWASP guidelines to uncover vulnerabilities, access control flaws, and server misconfigurations. You'll receive a clear report with severity ratings, exact reproduction steps, fix recommendations, and an executive summary—all conducted non-destructively. Ready to sign an NDA and start. Surbhi.
$875 USD in 10 days
6.7
6.7

Hi there, Saw your project for a full web app pentest covering OWASP Top 10 plus business logic, and the controlled / non-destructive testing requirement - I'll operate strictly within that. Your scope matches my daily work; I can test login flows, API endpoints and the IDOR concerns in the admin panels. What I'll do: ✅ Full black-box and grey-box test: Burp Suite + manual checks on auth, session cookies and access control. ✅ Vuln scan with OWASP ZAP / Nessus, STL review, port/service audit, then reference and rank findings. ✅ Solid remediation report with exact reproduction steps and CVE / effort-based priorities. Staged rollout so nothing slips - I test in dev/staging first, you'll okay everything before production. ✅ Burp Suite, OWASP ZAP, Nmap/Nessus ✅ OWASP Top 10 testing (SQLi, XSS, CSRF, broken auth) ✅ Risk-based manual testing for business logic access ✅ Clear deliverable: full report for devs + summary for your team ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ 300+ projects delivered, 280+ five-star reviews Why me: I'm available around the clock and I'll keep responses snappy - revises report till it's spot on. One question: do you have two separate environments (prod + staging), and would an NDA be a deal-breaker before access? Confident I'll have your app tested and report in 7 days for $900, and I can start right now. Khalil
$900 USD in 7 days
5.3
5.3

Hi there, Recently delivered Web Application Penetration Tests that uncovered authentication flaws, IDOR vulnerabilities, and security misconfigurations through a combination of black-box/grey-box testing and manual business logic validation, not just automated scans. You won't need to manage the assessment. I'll independently conduct a controlled, non-destructive penetration test, validate real attack vectors, and deliver a developer-ready report with severity ratings, reproduction steps, remediation guidance, and an executive summary for non-technical stakeholders. ? CISA Certified Security Expert ? AWS Solutions Architect – Professional ? AWS Solutions Architect – Associate ? 16+ Years in Cybersecurity, Cloud & DevSecOps My testing covers OWASP Top 10, authentication/authorization, APIs, session management, SSL/TLS, and server security using Burp Suite, OWASP ZAP, Nmap, Nessus, and manual verification. I'm comfortable signing an NDA and have experience producing audit-ready security reports with clear, actionable findings. Best regards, SHD
$1,125 USD in 7 days
5.3
5.3

Hello, I'm Rudra Kumar, an IT professional with an extensive background in safeguarding online platforms through comprehensive testing and quality assurance. I could be of great use in your pursuit for a seasoned cybersecurity expert to conduct a meticulous penetration test and standard security scan on your web application. My experience spans manual and automated testing, including vulnerability scanning and black/gray-box penetration testing, which aligns perfectly with your project requirements. Past employers have lauded my work in identifying potential attack vectors through an in-depth analysis of forms, APIs, user roles, etc., fortifying the defense against cyber threats which is crucial for any astute Penetration Tester. Additionally, my familiarity with tools like Burp Suite, OWASP ZAP, Nmap, Nessus exhibits my dexterity to work efficiently and effectively even in challenging environments. Over the years, I've gained robust experience in SSL/TLS configuration review, access control testing, server and infrastructure-level security check - which are also key aspects of this project. In line with your requirement, I'm comfortable signing all relevant NDAs to ensure complete confidentiality.
$1,250 USD in 7 days
5.0
5.0

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive black-box/grey-box web application penetration test aligned with the OWASP Testing Guide and PTES. Scope • Authentication, authorization, session management, and business logic testing • SQL Injection, XSS, CSRF, IDOR, command injection, SSRF, file upload, and security misconfigurations • API security assessment and access control validation • SSL/TLS review and server/infrastructure security assessment (open ports, exposed services, outdated software) Methodology & Tools Burp Suite, OWASP ZAP, Nmap, Nessus, SQLMap, Nuclei, Metasploit, and custom scripts, with all findings manually verified to eliminate false positives. Deliverables • Executive Summary for stakeholders • Detailed VAPT report with CVSS severity ratings • PoC evidence, screenshots, and reproduction steps • Actionable remediation guidance for each finding • Optional remediation retest after fixes Experience • Extensive experience securing SaaS, fintech, healthcare, e-commerce, and enterprise web applications • Redacted sample reports can be shared upon request • NDA-friendly and committed to non-destructive, responsible testing Timeline 5–7 business days, depending on application size and scope. Ready to start immediately once access and scope are confirmed.
$1,350 USD in 7 days
3.6
3.6

Hi, I can help you run a controlled web application penetration test that covers login areas, forms, APIs, user roles, admin panels, and the infrastructure around them. I’ve worked on assessments that combine automated scanning with manual testing, so I know where tools stop and real exploitation begins. My focus would be OWASP Top 10 issues, broken access control, session handling, SSL/TLS review, and any exposed services or outdated components. I’d start with a clear test plan and NDA, then move through black-box and grey-box testing using Burp Suite, OWASP ZAP, Nmap, and Nessus as needed. Every finding would include severity, reproduction steps, and practical remediation guidance, plus a concise summary for non-technical stakeholders. If you’d like, I can outline the timeline and testing approach next. Best regards, Gabriel
$750 USD in 15 days
1.0
1.0

Penetration testing will cover full black-box and grey-box methods focusing on authentication, access control, and APIs using industry-standard tools. Automated scans will target OWASP Top 10 vulnerabilities alongside manual checks of business logic, session management, and SSL/TLS configurations. Reports will be structured by severity with clear reproduction steps and remediation plans. Testing will follow strict non-destructive protocols with pre-approval for risky actions. What are the primary security concerns you aim to address with this penetration test?
$1,000 USD in 10 days
0.0
0.0

Dear Client, I reviewed your project requirements and I am interested in working with you. I have extensive experience delivering Computer Security, Technical Writing, Security Auditing, Penetration Testing, Network Security, Website Testing, Internet Security, Web Security and Risk Assessment. I focus on understanding the requirements clearly, providing a practical solution, and delivering accurate, well-documented work on schedule. I can review your existing materials, identify the best technical approach, and manage the project from planning through final delivery. You will receive clear communication, regular progress updates, and full support throughout the project. I am available to begin immediately and would be glad to discuss the scope, timeline, and budget. Best regards, Elijah M.
$1,400 USD in 7 days
0.0
0.0

Hi, You're seeking a controlled web app security test with clear, actionable findings and remediation steps. I’ve done practical web app pentests against login flows, APIs, and admin surfaces, delivering concise reports that map risks to fixes. Execution: I’d start by validating the current risk surface in a safe scope, run targeted manual testing backed by standard scanners, and reproduce findings with clear steps. I’d emphasize non-destructive testing and align on test windows and rollback procedures before any activity. One technical risk / key challenge: Isolating business-logic flaws while avoiding impact on live data can be tricky. Two clarification questions: 1) What environment is in scope (staging or production), and what are the allowed test windows? 2) Should we prioritize certain business flows (data access between roles) and are there data/privacy constraints we must honor? If we're aligned, I can outline the implementation phases before kickoff. Best regards, Brandon
$900 USD in 9 days
0.0
0.0

The hardest part of this job is the black-box approach to user roles and admin panels, so I will simulate different user accounts to access those areas. I will use Burp Suite Professional for proxying traffic and scanning, then manual testing with tools like SQLMap for SQL injection and browser developer tools for XSS and CSRF. For the automated scan, I will configure OWASP ZAP to cover the OWASP Top 10, focusing on injection flaws and broken authentication. I would not use purely automated scanning for the entire test. Automated scans miss context and many logic flaws, so they only scratch the surface. I am a Preferred Freelancer on Freelancer with a 5.0 rating, 100% on time and 100% on budget. What specific user roles and their associated permissions should I prioritize testing access to if multiple exist beyond a standard user and admin? A short call on Freelancer to settle the scope would cover the exact endpoints for the black-box testing and the list of user roles to be simulated.
$1,257 USD in 21 days
0.0
0.0

You’re commissioning a web application penetration test and security vulnerability assessment focused on exploitable risk, not just scanning. I will perform a controlled black-box/grey-box test covering login flows, forms, APIs, user roles, and any admin surfaces, paired with OWASP Top 10-aligned automated checks (e.g., SQL injection, XSS, CSRF, broken authentication, IDOR, and security misconfigurations). Findings will be delivered as a detailed, stakeholder-ready report with severity (Critical/High/Medium/Low), precise reproduction steps, and concrete remediation guidance per issue. I will also validate business logic and access control boundaries (including cross-account data exposure attempts), review SSL/TLS configuration, and assess server/infrastructure exposure such as open ports and exposed services. Session management, authentication, and authorization flows will be verified for weaknesses that enable privilege escalation or account takeover. Testing will be non-destructive and fully pre-approved for any action that could impact availability or data integrity. NDA compliance and clear professional English communication are built into the process.
$750 USD in 7 days
0.0
0.0

Hello, I think you are trying to get a complete security picture of your web application before any real-world threats can impact your users or business. I can help perform a controlled penetration test covering application logic, authentication flows, APIs, user roles, server configuration, and OWASP Top 10 vulnerabilities. I will start by understanding the application structure and access points, then perform both automated scanning and manual testing using security testing methods to identify weaknesses such as injection issues, access control problems, session flaws, and configuration risks. After testing, I’ll provide a clear report with severity levels, reproduction steps, and practical remediation recommendations that your technical team can easily follow. My focus will be finding real security risks without causing disruption, while giving you actionable insights to strengthen the application. Looking forward to work with you. Thanks
$850 USD in 10 days
0.0
0.0

Your requirement for controlled black-box/grey-box testing across login flows, APIs, user roles, admin panels, and infrastructure should be handled as a combined manual assessment and automated scan, not as a tool-generated report alone. I would begin with written scope, authorised targets, test accounts, rate limits, and rules of engagement, then assess OWASP Top 10 risks, broken access control, IDOR, session handling, authentication, CSRF, injection, XSS, API exposure, business-logic flaws, SSL/TLS, open ports, outdated services, and security misconfigurations. The two priorities would be clean implementation and maintainability, with every confirmed issue tied to reproducible evidence and remediation your developers can validate. Testing would use tools such as Burp Suite, OWASP ZAP, Nmap, and Nessus or equivalent, supported by manual verification to reduce false positives. Deliverables would include a severity-ranked technical report, reproduction steps, affected components, recommended fixes, and an executive summary suitable for non-technical stakeholders. Estimated timeline: 7 to 10 business days Fixed price: USD 1,000, assuming one production web application, related APIs, and a standard infrastructure footprint. I can sign an NDA and follow non-destructive testing rules. Any stress testing, exploit chaining, or action with downtime or data-loss risk would require written approval first.
$1,000 USD in 7 days
0.0
0.0

Hi there! Quick question: are you looking for testing against a specific compliance standard like PCI-DSS or HIPAA, or is this purely vulnerability-focused? Regardless, this is definitely something that I feel confident delivering on, given my past experience. I would love to discuss your project further! Looking forward hearing from you. kind regards, Corné
$900 USD in 7 days
0.0
0.0

As an experienced cybersecurity professional, I understand the gravity of web application security. Having conducted numerous penetration tests, successfully identified vulnerabilities, and remediated them before they were exploited, I am confident in my ability to provide unmatched security assessment for your web application. My past clients have consistently commended my clear and comprehensive reports which I will certainly extend to you. To tackle the OWASP Top 10 vulnerabilities, I am well-versed with industry-leading tools like Burp Suite, OWASP ZAP, and Nessus, among others. Moreover,I bring more than expertise; I bring a meticulous mindfulness to testing that rises above mere checkboxes. Understanding that your application deserves a non-destructive examination, I ensure sensitivity and approval at every step of the process. With me as your cybersecurity partner, expect nothing less than a robust final report with actionable insights tailored for both technical and non-technical stakeholders. Driven by a firm understanding of the evolving threat landscape, I will not only identify vulnerabilities but also provide recommendations for their effective mitigation. Let's connect soon and ensure the impenetrability of your web application!
$800 USD in 12 days
0.0
0.0

Dubai, United Arab Emirates
Payment method verified
Member since Sep 14, 2020
$250-750 USD
$100 USD
$70 USD
$50 USD
₹1500-12500 INR
$10-20 AUD
$8-15 USD / hour
$30-250 USD
₹12500-37500 INR
$30-250 USD
$250-750 USD
$2-8 USD / hour
₹75000-150000 INR
₹1500-12500 INR
$750-1500 USD
₹750-1250 INR / hour
min $50 USD / hour
£20-250 GBP
$30-250 AUD
₹12500-37500 INR
₹750-1250 INR / hour
$30-250 USD
$250-750 USD
€8-30 EUR