Ethical E-Commerce Security Audit
Budget: ₹1,500 – ₹12,500 INR
I need an experienced ethical hacker to perform a thorough security audit on my live e-commerce site. The goal is to discover and document every web-application vulnerability that could expose customer data, payment information, or site integrity.
You’ll have full, time-boxed access to a staging clone plus temporary credentials so you can run dynamic and manual tests with tools such as Burp Suite, OWASP ZAP, sqlmap, and any custom scripts you rely on. Static code review of critical modules (checkout, user auth, admin area) is also welcomed if it helps surface logic flaws beyond what black-box testing reveals.
Please follow OWASP Top 10 and industry best practices throughout the engagement. Any intrusive exploits must be executed cautiously to avoid disrupting production, and all findings must remain confidential.
Deliverables
• A concise executive summary and a detailed technical report
• Proof-of-concept evidence for each confirmed issue (screenshots, request/response pairs, or video)
• Severity rating, root cause analysis, and clear remediation guidance for every vulnerability
• A short re-test session once fixes are applied, to verify closure of critical issues
Let me know your estimated timeframe, preferred methodology, and any relevant certifications (e.g., OSCP, CEH) so we can schedule the test window and move forward.
You’ll have full, time-boxed access to a staging clone plus temporary credentials so you can run dynamic and manual tests with tools such as Burp Suite, OWASP ZAP, sqlmap, and any custom scripts you rely on. Static code review of critical modules (checkout, user auth, admin area) is also welcomed if it helps surface logic flaws beyond what black-box testing reveals.
Please follow OWASP Top 10 and industry best practices throughout the engagement. Any intrusive exploits must be executed cautiously to avoid disrupting production, and all findings must remain confidential.
Deliverables
• A concise executive summary and a detailed technical report
• Proof-of-concept evidence for each confirmed issue (screenshots, request/response pairs, or video)
• Severity rating, root cause analysis, and clear remediation guidance for every vulnerability
• A short re-test session once fixes are applied, to verify closure of critical issues
Let me know your estimated timeframe, preferred methodology, and any relevant certifications (e.g., OSCP, CEH) so we can schedule the test window and move forward.