Ethical Hacker Website Assessment
Budget: ₹2,500 – ₹0 INR
I need a certified ethical hacker to run a full-scope penetration test on my production website. The engagement must zero-in on two business-critical areas—user authentication and payment processing—while still giving me a clear picture of any other high-risk vulnerabilities you uncover.
Scope
• Black-box and gray-box testing techniques are both acceptable as long as you stay within the rules of engagement we set together.
• Tooling such as Burp Suite, OWASP ZAP, Nmap, nikto, sqlmap, or Metasploit is welcomed if it helps you surface real-world, reproducible issues.
Deliverables
1. Comprehensive vulnerability report (Executive Summary + Technical Detail).
2. Proof-of-concept evidence for each confirmed finding.
3. Prioritised remediation roadmap that ties fixes to industry best practices.
4. Final debrief session (live or recorded) to walk me through the results.
Acceptance Criteria
• Every identified issue must be mapped to CVSS or an equivalent scoring system.
• Recommendations must be actionable and aligned with current OWASP Top 10 guidance.
• No production data may be exfiltrated or altered during testing.
To be considered, please include:
– Your relevant certifications (e.g., OSCP, CEH, GPEN).
– A brief summary of similar web assessments you have completed.
– Estimated timeline and price breakdown by testing phase.
This assessment is strictly for authorised, legal security testing. I will provide written permission before any testing begins and expect you to operate within ethical hacking standards at all times.
Scope
• Black-box and gray-box testing techniques are both acceptable as long as you stay within the rules of engagement we set together.
• Tooling such as Burp Suite, OWASP ZAP, Nmap, nikto, sqlmap, or Metasploit is welcomed if it helps you surface real-world, reproducible issues.
Deliverables
1. Comprehensive vulnerability report (Executive Summary + Technical Detail).
2. Proof-of-concept evidence for each confirmed finding.
3. Prioritised remediation roadmap that ties fixes to industry best practices.
4. Final debrief session (live or recorded) to walk me through the results.
Acceptance Criteria
• Every identified issue must be mapped to CVSS or an equivalent scoring system.
• Recommendations must be actionable and aligned with current OWASP Top 10 guidance.
• No production data may be exfiltrated or altered during testing.
To be considered, please include:
– Your relevant certifications (e.g., OSCP, CEH, GPEN).
– A brief summary of similar web assessments you have completed.
– Estimated timeline and price breakdown by testing phase.
This assessment is strictly for authorised, legal security testing. I will provide written permission before any testing begins and expect you to operate within ethical hacking standards at all times.