White-Box Web App Penetration
Budget: $30 – $250 USD
I am ready to put my in-house web application through a thorough white-box penetration test and need a seasoned ethical hacker to run point. Because I can supply source code, architecture docs, and admin-level credentials, you will have full visibility to explore logic flaws, insecure configurations, and anything else that could turn into a real-world exploit.
A key requirement is prior experience registering newly discovered vulnerabilities in official government vulnerability databases or repositories; I will rely on you not only to uncover issues but also to craft the correct disclosure package so the finding can be submitted and tracked according to policy.
Scope
• Inspect the entire codebase, APIs, and third-party integrations.
• Execute manual and automated testing using tools you prefer—Burp Suite, OWASP ZAP, Metasploit, custom scripts, etc.—while documenting every step.
• Provide a concise risk rating and remediation guidance for each confirmed vulnerability.
• Prepare the formal write-up for submission to the relevant government CVE or equivalent repository, following their formatting guidelines.
Acceptance Criteria
1. Penetration test report (PDF) with reproduction steps, impact analysis, and prioritized fixes.
2. Proof-of-concept exploits or screenshots for each critical or high finding.
3. A separate disclosure package ready for government database submission, including suggested CVE description text.
I’ll coordinate access and timelines once we agree on the engagement. If you have verifiable white-box web testing success stories—especially ones that led to an official CVE assignment—let’s connect.
A key requirement is prior experience registering newly discovered vulnerabilities in official government vulnerability databases or repositories; I will rely on you not only to uncover issues but also to craft the correct disclosure package so the finding can be submitted and tracked according to policy.
Scope
• Inspect the entire codebase, APIs, and third-party integrations.
• Execute manual and automated testing using tools you prefer—Burp Suite, OWASP ZAP, Metasploit, custom scripts, etc.—while documenting every step.
• Provide a concise risk rating and remediation guidance for each confirmed vulnerability.
• Prepare the formal write-up for submission to the relevant government CVE or equivalent repository, following their formatting guidelines.
Acceptance Criteria
1. Penetration test report (PDF) with reproduction steps, impact analysis, and prioritized fixes.
2. Proof-of-concept exploits or screenshots for each critical or high finding.
3. A separate disclosure package ready for government database submission, including suggested CVE description text.
I’ll coordinate access and timelines once we agree on the engagement. If you have verifiable white-box web testing success stories—especially ones that led to an official CVE assignment—let’s connect.