Website Security Assessment Needed
Budget: ₹12,500 – ₹37,500 INR
I need a certified ethical hacker to run a thorough, external-facing security assessment on my website. The goal is simple: show me, with evidence, whether an attacker can break in, and explain how to stop them.
You will probe the full web stack just as a real adversary would—reconnaissance, vulnerability discovery, exploitation attempts, and post-exploitation validation—without disrupting normal service. I am particularly interested in anything that compromises user authentication, exposes unencrypted data, or allows malware injection, but I want the engagement to remain broad so nothing is missed.
Please work with standard tools such as Burp Suite, OWASP ZAP, Nmap, sqlmap, Metasploit, or any custom scripts you prefer, and follow OWASP Testing Guide methodology. Throughout the test, keep logs of every step so results are fully reproducible.
Deliverables (all items required for sign-off):
• Executive summary written in plain language
• Detailed technical report listing each finding, severity (CVSS), proof-of-concept screenshots or request/response captures, and clear remediation advice
• Clean retest results confirming that fixes have closed the holes (optional second pass, billed separately if substantial new testing is needed)
I will provide the domain, staging credentials if necessary, and a signed authorization letter so you can work without legal concerns. Let me know your estimated timeline for the initial assessment and report.
You will probe the full web stack just as a real adversary would—reconnaissance, vulnerability discovery, exploitation attempts, and post-exploitation validation—without disrupting normal service. I am particularly interested in anything that compromises user authentication, exposes unencrypted data, or allows malware injection, but I want the engagement to remain broad so nothing is missed.
Please work with standard tools such as Burp Suite, OWASP ZAP, Nmap, sqlmap, Metasploit, or any custom scripts you prefer, and follow OWASP Testing Guide methodology. Throughout the test, keep logs of every step so results are fully reproducible.
Deliverables (all items required for sign-off):
• Executive summary written in plain language
• Detailed technical report listing each finding, severity (CVSS), proof-of-concept screenshots or request/response captures, and clear remediation advice
• Clean retest results confirming that fixes have closed the holes (optional second pass, billed separately if substantial new testing is needed)
I will provide the domain, staging credentials if necessary, and a signed authorization letter so you can work without legal concerns. Let me know your estimated timeline for the initial assessment and report.