Comprehensive Web App Pen Test
Budget: ₹75,000 – ₹150,000 INR
I’ve built a custom web application and it’s almost ready for production. Before the public rollout, I want a rigorous penetration test that will expose any weakness and help tighten every layer of security. The assessment must be hands-on and realistic, covering the full stack rather than a purely theoretical review.
Scope
My priorities are clear:
• Code review – comb through the source for injection points, authentication flaws, insecure dependencies, and logic errors.
• Network-level probing – map open ports, misconfigured firewalls, and potential lateral-movement paths.
• Server configuration – evaluate patch levels, TLS setup, permissions, and hardening of the underlying OS and web server.
Primary Goal
The sole purpose is to improve the overall security posture of the application; compliance check-boxes are secondary. I expect actionable insights that can be fed straight into our development pipeline.
Deliverables
1. Executive summary highlighting critical risks in plain language.
2. Technical report detailing each finding, proof-of-concept exploits, CVSS-based severity, and clear remediation steps.
3. Interactive debrief call or recorded walkthrough so my team can ask clarifying questions.
4. (Optional, if time permits) A follow-up validation test once fixes are applied.
Tools & Methodology
Feel free to employ industry-standard tooling such as Burp Suite, OWASP ZAP, Nmap, Nikto, or custom scripts; just document the methodology so results are reproducible. All testing must respect the agreed time window and remain within the provided staging environment.
If you thrive on uncovering hard-to-find vulnerabilities and can present findings in a way my developers will immediately act upon, let’s lock in a schedule.
Scope
My priorities are clear:
• Code review – comb through the source for injection points, authentication flaws, insecure dependencies, and logic errors.
• Network-level probing – map open ports, misconfigured firewalls, and potential lateral-movement paths.
• Server configuration – evaluate patch levels, TLS setup, permissions, and hardening of the underlying OS and web server.
Primary Goal
The sole purpose is to improve the overall security posture of the application; compliance check-boxes are secondary. I expect actionable insights that can be fed straight into our development pipeline.
Deliverables
1. Executive summary highlighting critical risks in plain language.
2. Technical report detailing each finding, proof-of-concept exploits, CVSS-based severity, and clear remediation steps.
3. Interactive debrief call or recorded walkthrough so my team can ask clarifying questions.
4. (Optional, if time permits) A follow-up validation test once fixes are applied.
Tools & Methodology
Feel free to employ industry-standard tooling such as Burp Suite, OWASP ZAP, Nmap, Nikto, or custom scripts; just document the methodology so results are reproducible. All testing must respect the agreed time window and remain within the provided staging environment.
If you thrive on uncovering hard-to-find vulnerabilities and can present findings in a way my developers will immediately act upon, let’s lock in a schedule.