Black-Box Web & App PenTest

Job ID: 39839417

Budget: $30 – $250 USD

I need a thorough, black-box penetration test on both my production website and its companion mobile app. You’ll start with nothing more than the public URL and the app-store links so the exercise mirrors a real-world external attack.

The objective is simple: identify and document every exploitable weakness before someone else does. That means probing authentication flows, API calls, server configurations, data storage, and any third-party integrations you can legitimately reach—while staying within legal boundaries and steering clear of DoS or social-engineering tactics.

To keep things concrete, here’s what I expect you to hand over:

• An executive-level summary of overall risk
• A detailed, OWASP-style technical report with proof-of-concept evidence, reproduction steps, and severity ranking
• Clear remediation advice, ordered by priority

Methodologies aligned with the OWASP Web Security Testing Guide, Mobile Security Testing Guide, or similar standards are preferred, and I’m fine with tools like Burp Suite, OWASP ZAP, Nmap, Wireshark, or MobSF as long as they’re used responsibly.

I’d like preliminary findings within a week and the final report no later than two weeks after kickoff. When you bid, briefly outline your approach and list any relevant certifications (OSCP, CEH, etc.) or past black-box engagements. Let’s see how secure my platforms really are.