Expert Mobile Application VAPT (iOS/Android) & API Penetration Testing

Job ID: 40370034

Budget: ₹75,000 – ₹150,000 INR

Project Description:
We are seeking a highly skilled and experienced cybersecurity professional to conduct a comprehensive Vulnerability Assessment and Penetration Test (VAPT) on our mobile application.

The primary goal is to identify, assess, and report on security vulnerabilities within the mobile client and its associated backend APIs. The ideal candidate will have a proven track record in mobile security, follow industry-best practices (such as OWASP MASVS), and provide a detailed, actionable report.

About the Application:

Application Name: SecureApp
Platform(s): iOS/Android
Primary Function: An e-commerce platform for handmade goods
Technology Stack (if known):React Native, Backend is Node.js

Scope of Work:
The VAPT should cover, but is not limited to, the following areas:

1. Mobile Application Client-Side Testing (for [iOS/Android/Both]):

Static Analysis (SAST): Analyze the application binary (.ipa/.apk) for security flaws without executing it. This includes checking for hardcoded secrets, insecure code practices, and vulnerable libraries.
Dynamic Analysis (DAST): Test the application in a running state to identify runtime vulnerabilities.
Insecure Data Storage: Check for sensitive data (credentials, PII, tokens) stored insecurely on the device (e.g., in SharedPreferences, Plist files, SQLite databases).
Insecure Communication: Analyze network traffic to/from the app to ensure encryption is properly implemented (TLS/SSL) and to check for certificate pinning issues.
Client-Side Injection: Test for vulnerabilities like SQL Injection in local databases or Cross-Site Scripting (XSS) in WebViews.
Broken Authentication & Session Management: Test for weaknesses in login, logout, session handling, and credential management on the client side.
Code Obfuscation & Reverse Engineering Resistance: Assess the difficulty of reverse-engineering the application.

2. API / Server-Side Testing:
API Endpoint Discovery and Mapping: Identify all API endpoints used by the mobile application.
Authentication & Authorization Flaws: Test for broken object-level authorization (BOLA/IDOR), broken function-level authorization, and other access control issues.
Injection Attacks: Test for SQL Injection, NoSQL Injection, Command Injection, etc., on all API endpoints that accept user input.
Sensitive Data Exposure: Ensure APIs are not leaking sensitive user or system information.
Security Misconfiguration: Check for insecure server configurations, verbose error messages, and other misconfigurations.
Mass Assignment: Test for vulnerabilities where an attacker can modify object properties they should not have access to.
Rate Limiting & Resource Management: Test for weaknesses in API rate limiting that could lead to DoS or brute-force attacks.

Deliverables:
Comprehensive VAPT Report: A detailed report in PDF format containing:
Executive Summary: A high-level overview of the findings for non-technical stakeholders.
Technical Details: A thorough description of each vulnerability found.
Vulnerability Classification: Each finding must be ranked by severity (e.g., Critical, High, Medium, Low) using a standard like CVSS.
Proof of Concept (PoC): Clear, step-by-step instructions, screenshots, and/or code snippets to reproduce each vulnerability.
Remediation Guidance: Actionable recommendations and best practices for our development team to fix the identified vulnerabilities.
Debriefing Call (Optional but preferred): A one-hour video call to walk through the report, answer questions, and clarify findings with our technical team.
(Optional Phase 2) Retesting: After we have implemented the fixes, we may require a follow-up engagement to verify that the vulnerabilities have been successfully patched. Please state your rate for retesting.

Required Skills and Experience:
Proven experience in mobile application penetration testing (iOS and/or Android).
Strong understanding of the OWASP Mobile Top 10 and the OWASP Mobile Application Security Verification Standard (MASVS).
Expertise in testing APIs and deep knowledge of the OWASP API Security Top 10.
Proficiency with security tools such as Burp Suite Pro, MobSF, Frida, Ghidra, jadx, and others.
Relevant cybersecurity certifications are a strong plus (e.g., OSCP, eMAPT, GMOB, C-PENT).
Excellent written and verbal communication skills in English.
Ability to write clear, professional, and actionable reports.

What We Will Provide:
Access to the application builds (.apk and/or .ipa via TestFlight/Firebase App Distribution).
At least two sets of test user credentials (e.g., a standard user, and an admin user if applicable).
Access to our development team for any necessary clarifications during the testing period.


How to Apply:
To be considered for this project, please provide the following in your proposal:
A brief overview of your experience in mobile and API VAPT.
Describe your proposed methodology/approach for this project.
A sanitized (all client information removed) sample of a previous VAPT report you have authored. This is crucial for us to evaluate the quality of your work.
Your estimated timeline to complete the full assessment and deliver the report.
To show you have read this post carefully, please start your proposal with the word "SecureApp".