Comprehensive Web App Penetration Test
Budget: ₹12,500 – ₹37,500 INR
A full-scope penetration test is required on my production web application with special attention paid to authentication and authorization workflows, input validation and sanitization routines, session management, and any additional vectors you deem necessary for a modern OWASP-aligned assessment. Automated scanning is welcome, yet the emphasis should remain on thorough manual exploitation using tools such as Burp Suite, Kali Linux, or equivalents, so that business-logic flaws are uncovered alongside technical ones.
Please include a redacted sample or concise summary of past work that demonstrates report structure, depth of findings, and remediation guidance. No other application materials are necessary at this stage.
Deliverables expected:
• An executive summary and detailed technical report covering every vulnerability found, mapped to risk ratings.
• Actionable remediation recommendations with references.
• Proof-of-concept evidence (screenshots, request/response pairs, or scripts) for critical and high findings.
• A short retest after fixes, validating that issues have been resolved.
The engagement should follow responsible disclosure practices, be performed against the agreed testing environment only, and leave the application stable throughout.
Please include a redacted sample or concise summary of past work that demonstrates report structure, depth of findings, and remediation guidance. No other application materials are necessary at this stage.
Deliverables expected:
• An executive summary and detailed technical report covering every vulnerability found, mapped to risk ratings.
• Actionable remediation recommendations with references.
• Proof-of-concept evidence (screenshots, request/response pairs, or scripts) for critical and high findings.
• A short retest after fixes, validating that issues have been resolved.
The engagement should follow responsible disclosure practices, be performed against the agreed testing environment only, and leave the application stable throughout.