Ethical Web App Pen Test

Job ID: 39979464

Budget: ₹1,500 – ₹12,500 INR

I need a thorough, ethical penetration test carried out on our customer-facing web application. The sole purpose is security testing, so every step must respect legal boundaries and adhere to recognized standards like OWASP and NIST.

Scope
The assessment should simulate real-world attacker tactics against the entire stack—front-end, back-end, APIs, session management, authentication, and authorization flows. Black-box or grey-box techniques are fine as long as you explain your approach up front. Tooling such as Burp Suite, OWASP ZAP, Metasploit, Nmap, or custom scripts is welcome; just keep detailed logs for transparency.

Deliverables (all required)
• Methodology document outlining test phases and tools
• Risk-ranked vulnerability report (PDF) with CVSS scores and clear remediation guidance
• Proof-of-concept evidence for every exploitable finding (screenshots, request/response pairs, or video)
• Debrief call or recorded walkthrough to discuss results and answer questions
• Optional: one re-test after fixes are applied, included as a separate milestone

Acceptance Criteria
A report is considered complete when each discovered issue is reproducible, properly documented, and mapped to an industry standard such as the OWASP Top 10. No critical or high findings should remain unverified or without mitigation advice.

Timeline is flexible within reason, but I’d like the initial findings within two weeks of project start so we can schedule the remediation sprint promptly. Let me know your preferred approach, estimated duration, and any prerequisites you need (e.g., staging credentials, test data).