Comprehensive Web App Pen-Test

Job ID: 39846493

Budget: ₹1,500 – ₹12,500 INR

I need a seasoned security tester to run a full-scale penetration assessment against my public-facing gaming website. The scope includes the core web app, its related APIs, and any exposed admin panels. Your job is to uncover everything from classic OWASP Top 10 issues—XSS, SQLi, CSRF, authentication and authorization flaws—to subtle business-logic weaknesses unique to a fast-paced gaming platform. Misconfigured headers, unsafe cookies, weak session handling, and server-side slip-ups are all in play.

Here’s how I see the engagement:

• Recon & manual/exploitive testing using industry tools (Burp Suite, OWASP ZAP, Nmap, etc.)
• Clear, step-by-step vulnerability report: proof-of-concept payloads, screenshots, affected URLs, severity ratings, and risk rationale
• Actionable remediation guidance written for both developers and DevOps
• One round of free retesting after my team applies the fixes to confirm closure

When you respond, attach a concise project proposal outlining your methodology, timelines, and any relevant past work you can publicly disclose.