Comprehensive Web Pen-Test
Budget: $750 – $1,500 USD
I am looking for a seasoned security specialist who can run a full-cycle, OWASP Top 10–oriented penetration test on our web application. The engagement must cover information gathering, vulnerability verification, exploitation for risk validation, and finally a polished report.
What matters most:
• You are genuinely comfortable hunting for SQLi, XSS, CSRF, RCE, SSRF, business-logic flaws and similar issues.
• All testing is performed directly by you—no re-outsourcing and no leakage of data, code or credentials.
• Burp Suite will be the primary toolbox; if you prefer supplementing it with OWASP ZAP or Nmap, that is fine as long as the results remain consistent.
• You can show prior enterprise-grade work or at least a sample report so I can assess depth and style.
Deliverables I expect at hand-off:
1. A report that clearly states each finding’s description and risk, step-by-step reproduction, and actionable remediation advice.
2. Separate attachment of raw POC traffic or scripts (where applicable) so our developers can replay and verify.
3. A one-page executive summary suitable for non-technical stakeholders.
Please outline:
– Your preferred pricing model (per project, per vulnerability, or daily).
– Estimated timeline from kick-off to final report.
– A brief test plan describing methodology and key milestones.
I reply quickly, will provide the target scope and staging creds, and can set up real-time channels for smooth communication. Let’s secure the app together.
What matters most:
• You are genuinely comfortable hunting for SQLi, XSS, CSRF, RCE, SSRF, business-logic flaws and similar issues.
• All testing is performed directly by you—no re-outsourcing and no leakage of data, code or credentials.
• Burp Suite will be the primary toolbox; if you prefer supplementing it with OWASP ZAP or Nmap, that is fine as long as the results remain consistent.
• You can show prior enterprise-grade work or at least a sample report so I can assess depth and style.
Deliverables I expect at hand-off:
1. A report that clearly states each finding’s description and risk, step-by-step reproduction, and actionable remediation advice.
2. Separate attachment of raw POC traffic or scripts (where applicable) so our developers can replay and verify.
3. A one-page executive summary suitable for non-technical stakeholders.
Please outline:
– Your preferred pricing model (per project, per vulnerability, or daily).
– Estimated timeline from kick-off to final report.
– A brief test plan describing methodology and key milestones.
I reply quickly, will provide the target scope and staging creds, and can set up real-time channels for smooth communication. Let’s secure the app together.