Comprehensive OTP Pen-Test

Job ID: 40487273

Budget: $500 – $1,500 USD

I need a seasoned ethical hacker to assess the security of our one-time-password (OTP) verification flow from end to end. The engagement is fully authorised and limited to our staging environment; no production traffic may be disrupted.

Scope of the test
• Probe OTP generation and validation logic for weaknesses or predictable patterns
• Attempt request manipulation, parameter tampering, and replay attacks to gauge bypass potential
• Evaluate rate-limiting and brute-force defences, including lockout and alerting mechanisms
• Review session handling during the OTP step to spot fixation, hijack, or privilege-escalation vectors
• Inspect related APIs and webhook calls for improper authentication, excessive data exposure, or logic flaws
• Analyse password-reset and account-verification flows that rely on OTP to uncover business-logic gaps

Deliverables (submit in a single, well-structured report)
1. Detailed vulnerability list with CVSS or comparable risk severity for each finding
2. Proof-of-concept steps or scripts that reliably reproduce confirmed issues
3. Clear, prioritised remediation recommendations and any quick-win configuration fixes
4. Executive summary suitable for non-technical stakeholders

Acceptance criteria
• All findings must be reproducible in our environment.
• Testing stays within the defined scope and follows responsible disclosure standards.
• No customer data is altered or service availability affected.
• Final report passes internal review for clarity and completeness.

Preferred tools include Burp Suite, OWASP ZAP, or comparable intercept proxies, but feel free to bring any specialised scripts you rely on. If you can deliver within two weeks and communicate progress through concise daily notes, I’d like to hear how you’d approach this assessment and a quick overview of similar OTP engagements you’ve handled.