Bank Loan App Security Audit
Budget: ₹2,500 – ₹0 INR
I need a seasoned ethical hacker to run a comprehensive penetration test on our in-production bank-loan web application. The scope is broad: the public-facing web interface, every documented and undocumented API endpoint, and the underlying database layer must all be reviewed. While I expect you to cover the full OWASP Top 10, I am particularly worried about SQL Injection and Server-Side Request Forgery, so those areas should receive extra scrutiny.
Our environment already has an IDS, an enterprise-grade WAF, and mandatory 2FA in place. Please factor these controls into your test plan so that any bypasses or weaknesses are highlighted rather than masked.
Deliverable
• A clear, actionable report that ranks each finding by risk, shows reproducible steps, and recommends precise fixes or compensating controls. Screenshots, PoC payloads, and log extracts are expected where relevant.
Other notes
• Prior FinTech or banking experience will be a plus, as regulatory language and data-handling nuances matter here.
• All activity must remain within the bounds of our signed NDA and the agreed engagement window.
• You’ll be supplied with staging credentials, API documentation, and a secure channel for reporting critical issues in real time.
If this fits your expertise, let’s lock dates and methodology.
Our environment already has an IDS, an enterprise-grade WAF, and mandatory 2FA in place. Please factor these controls into your test plan so that any bypasses or weaknesses are highlighted rather than masked.
Deliverable
• A clear, actionable report that ranks each finding by risk, shows reproducible steps, and recommends precise fixes or compensating controls. Screenshots, PoC payloads, and log extracts are expected where relevant.
Other notes
• Prior FinTech or banking experience will be a plus, as regulatory language and data-handling nuances matter here.
• All activity must remain within the bounds of our signed NDA and the agreed engagement window.
• You’ll be supplied with staging credentials, API documentation, and a secure channel for reporting critical issues in real time.
If this fits your expertise, let’s lock dates and methodology.
Related categories:
Web Security
Compliance
Penetration Testing
Network Security
Risk Assessment
Data Protection