Gray-Box SaaS Pen Test
Budget: €30 – €250 EUR
I need a full gray-box penetration test on my SaaS platform’s web application. You will have test credentials and light documentation, so please plan to combine code-assisted inspection with real-world attack simulation.
Scope
• Web application only. The API layer and database are out of scope for this engagement, though findings that spill over are welcome.
• Critical areas: user authentication flows, every data-input form, and the “Server acess” feature that exposes limited server-side actions from the UI.
What I expect as deliverables
1. Detailed technical report (vulnerabilities, risk rating, step-by-step replication, remediation guidance).
2. Executive-level summary suitable for non-technical stakeholders.
3. Proof-of-concept scripts or screenshots for each confirmed finding.
4. Optional short retest once fixes are deployed (include this in your timeline).
Your methodology should align with OWASP Web Security Testing Guide and industry best practices, leveraging tools such as Burp Suite, OWASP ZAP, or similar combined with manual verification.
Please outline your approach, sample report format, and estimated turnaround when responding.
Scope
• Web application only. The API layer and database are out of scope for this engagement, though findings that spill over are welcome.
• Critical areas: user authentication flows, every data-input form, and the “Server acess” feature that exposes limited server-side actions from the UI.
What I expect as deliverables
1. Detailed technical report (vulnerabilities, risk rating, step-by-step replication, remediation guidance).
2. Executive-level summary suitable for non-technical stakeholders.
3. Proof-of-concept scripts or screenshots for each confirmed finding.
4. Optional short retest once fixes are deployed (include this in your timeline).
Your methodology should align with OWASP Web Security Testing Guide and industry best practices, leveraging tools such as Burp Suite, OWASP ZAP, or similar combined with manual verification.
Please outline your approach, sample report format, and estimated turnaround when responding.
Related categories:
Web Security
Compliance
Penetration Testing
Network Security
Risk Assessment
Data Protection
API Testing