Comprehensive Website Penetration Test
Budget: $250 – $750 USD
I need a seasoned tester to run a full-scale penetration test on my production website. This is not a simple vulnerability scan—I’m after a true adversary-style assessment that digs into every layer of the stack. Please probe the application itself, the underlying network paths, and the database environment so I can see how each tier stands up to real-world attack techniques.
Scope
• Web application: session handling, business logic, input validation, file upload points, and any third-party integrations
• Network layer: open ports, firewall rules, lateral movement potential, VPN or cloud perimeter controls
• Database layer: authentication controls, injection resistance, privilege escalation paths, and data-at-rest exposure
Deliverables
• A concise executive summary that highlights overall risk posture
• A detailed technical report outlining each discovered vulnerability with CVSS score, proof-of-concept steps, and clear remediation guidance
• Annotated screenshots or recordings that demonstrate exploitation where relevant
• A debrief call (or written Q&A) to walk me through findings and recommended next steps
• Optional: one round of retesting after fixes to confirm closure
Tools and methodology are up to you—Burp Suite, Nmap, Metasploit, SQLmap, custom scripts—so long as your approach follows industry best practices (OWASP, PTES, NIST). All testing must respect legal boundaries; I will supply explicit written authorization before you begin.
Let me know your estimated timeline, any prerequisites you’ll need from me (credentials, staging URLs, whitelisted IPs), and a brief outline of your past work that shows you can safely execute a comprehensive penetration test across application, network, and database layers.
Scope
• Web application: session handling, business logic, input validation, file upload points, and any third-party integrations
• Network layer: open ports, firewall rules, lateral movement potential, VPN or cloud perimeter controls
• Database layer: authentication controls, injection resistance, privilege escalation paths, and data-at-rest exposure
Deliverables
• A concise executive summary that highlights overall risk posture
• A detailed technical report outlining each discovered vulnerability with CVSS score, proof-of-concept steps, and clear remediation guidance
• Annotated screenshots or recordings that demonstrate exploitation where relevant
• A debrief call (or written Q&A) to walk me through findings and recommended next steps
• Optional: one round of retesting after fixes to confirm closure
Tools and methodology are up to you—Burp Suite, Nmap, Metasploit, SQLmap, custom scripts—so long as your approach follows industry best practices (OWASP, PTES, NIST). All testing must respect legal boundaries; I will supply explicit written authorization before you begin.
Let me know your estimated timeline, any prerequisites you’ll need from me (credentials, staging URLs, whitelisted IPs), and a brief outline of your past work that shows you can safely execute a comprehensive penetration test across application, network, and database layers.