Penetration Testing for Servers and Webpages
Budget: $250 – $750 USD
I need an experienced penetration tester to conduct a comprehensive external security assessment on 3 servers and 6 public webpages.
Requirements include:
- Port scanning
- Vulnerability scanning
- Manual exploitation attempts
- OWASP Top 10 web application testing
Deliverables:
- Professional PDF report detailing:
- Identified vulnerabilities
- Risk ratings
- Remediation advice
Please provide:
- Testing methodology
- Tools used (Metasploit, Nmap, Burp Suite, etc.)
- Sample report
Ideal Skills and Experience:
- Certified ethical hacker
- Strong reporting capabilities
- Experience with security assessments
Expected Tools and Techniques:
• Automated scanners (e.g., OpenVAS, Nessus, Nikto, Wfuzz).
• Manual exploitation (e.g., Metasploit, custom scripts).
• Web app testing (Burp Suite, OWASP ZAP, manual inspection).
Expected Outputs:
• Executive Summary for management.
• Technical Report for IT staff.
• List of vulnerabilities categorized by risk (Critical, High, Medium, Low).
• Screenshots or logs proving findings.
• Prioritized list of remediation steps.
Contract Conditions:
• Penetration test is allowed only against specific IP ranges and domains provided.
• Testing must occur within agreed hours if required (to avoid downtime).
• Pen-tester must delete any data accessed as part of the test after the engagement.
Requirements include:
- Port scanning
- Vulnerability scanning
- Manual exploitation attempts
- OWASP Top 10 web application testing
Deliverables:
- Professional PDF report detailing:
- Identified vulnerabilities
- Risk ratings
- Remediation advice
Please provide:
- Testing methodology
- Tools used (Metasploit, Nmap, Burp Suite, etc.)
- Sample report
Ideal Skills and Experience:
- Certified ethical hacker
- Strong reporting capabilities
- Experience with security assessments
Expected Tools and Techniques:
• Automated scanners (e.g., OpenVAS, Nessus, Nikto, Wfuzz).
• Manual exploitation (e.g., Metasploit, custom scripts).
• Web app testing (Burp Suite, OWASP ZAP, manual inspection).
Expected Outputs:
• Executive Summary for management.
• Technical Report for IT staff.
• List of vulnerabilities categorized by risk (Critical, High, Medium, Low).
• Screenshots or logs proving findings.
• Prioritized list of remediation steps.
Contract Conditions:
• Penetration test is allowed only against specific IP ranges and domains provided.
• Testing must occur within agreed hours if required (to avoid downtime).
• Pen-tester must delete any data accessed as part of the test after the engagement.
Related categories:
Testing / QA
Computer Security
Software Testing
Website Testing
Internet Security