Web App Vulnerability Pentest - 04/08/2026 08:24 EDT
Budget: ₹750 – ₹1,250 INR
I need an experienced penetration tester to run a thorough assessment of my production web application. The primary objective is to identify vulnerabilities, with particular attention paid to three high-risk zones:
• Authentication and authorization logic
• Database exposure paths (SQL injection, insecure queries, weak configuration)
• Input validation and handling that could open the door to XSS, command injection, or similar issues
I will provide you with staging and live URLs, test accounts, and any required API keys. Please treat the exercise as a real-world black/grey-box engagement—no source code will be shared. You may use industry-standard tooling such as Burp Suite, OWASP ZAP, sqlmap, or custom scripts as you see fit, as long as methodology aligns with the OWASP Testing Guide.
Deliverables expected:
1. A concise executive summary highlighting the overall risk level.
2. A technical report detailing each finding, its CVSS score, proof-of-concept evidence (screenshots, intercepted requests), and clear remediation advice.
3. A brief follow-up call or chat to walk me through the critical issues.
The engagement must respect legal and ethical boundaries; only test what I authorize and keep all data confidential. If this scope matches your expertise, let’s get started.
• Authentication and authorization logic
• Database exposure paths (SQL injection, insecure queries, weak configuration)
• Input validation and handling that could open the door to XSS, command injection, or similar issues
I will provide you with staging and live URLs, test accounts, and any required API keys. Please treat the exercise as a real-world black/grey-box engagement—no source code will be shared. You may use industry-standard tooling such as Burp Suite, OWASP ZAP, sqlmap, or custom scripts as you see fit, as long as methodology aligns with the OWASP Testing Guide.
Deliverables expected:
1. A concise executive summary highlighting the overall risk level.
2. A technical report detailing each finding, its CVSS score, proof-of-concept evidence (screenshots, intercepted requests), and clear remediation advice.
3. A brief follow-up call or chat to walk me through the critical issues.
The engagement must respect legal and ethical boundaries; only test what I authorize and keep all data confidential. If this scope matches your expertise, let’s get started.