Mobile App Network Security Audit

Job ID: 40404906

Budget: ₹600 – ₹1,500 INR

Our consumer-facing mobile application will soon move from staging to production, and I want a focused review of every network interaction it makes. The goal is to confirm that the APIs, sockets, and any third-party calls are locked down, correctly authenticated, and safe from man-in-the-middle risks.

Scope of work
• Map all outbound and inbound traffic from the current iOS and Android builds.
• Pen-test the API gateway, verify TLS implementation, and attempt common network attacks (MITM, SSL-strip, DNS spoofing).
• Analyse certificate pinning, token handling, and session expiry logic to be sure no credentials can be intercepted or replayed.
• Provide clear, actionable fixes for any weaknesses you uncover, ranked by severity and effort.

Acceptance criteria
1. A written report that lists each finding, the evidence, and a recommended remediation step.
2. Proof-of-concept scripts or captures for critical issues.
3. A retest summary showing that all high-risk items are resolved (or a plan is in place).

Tooling expectations: Burp Suite, OWASP ZAP, Wireshark, or comparable network-focused suites are fine as long as the output is reproducible and easy for our internal team to verify.

The project is complete once the final report and retest summary are accepted and our mobile build clears the high-risk category.