Gray-Box Web App Security -- 2
Budget: ₹12,500 – ₹37,500 INR
Gray-Box Web Application Security Audit
We are seeking a comprehensive gray-box penetration test for a production web application. Limited internal access, including valid user credentials and basic application architecture information, will be provided to simulate a realistic attacker perspective while enabling deeper security analysis.
The assessment should focus on:
* Authentication & Authorization testing (role escalation, privilege bypass, brute-force, MFA validation)
* Input Validation vulnerabilities (SQL Injection, XSS, command injection, insecure file upload, etc.)
* Session Management testing (session fixation, cookie security, token handling, logout functionality, idle timeout)
The testing methodology should follow OWASP Top 10 and industry-standard penetration testing practices. Automated tools may be used for discovery, but all findings must be manually verified to eliminate false positives.
Preferred tools and techniques:
* Burp Suite
* OWASP ZAP
* Nmap
* Nikto
* SQLmap
* Nuclei
* Manual testing and verification
Expected Deliverables:
1. Executive summary outlining overall security posture
2. Detailed technical report with:
* Vulnerability description
* CVSS severity rating
* Reproduction steps
* Screenshots/PoC
* Remediation recommendations
3. Severity-based vulnerability matrix
4. One retest after remediation with updated findings
5. Responsible handling and secure disposal of any sensitive data collected during testing
The final report should be delivered in both PDF and editable format within the agreed timeline.
We are seeking a comprehensive gray-box penetration test for a production web application. Limited internal access, including valid user credentials and basic application architecture information, will be provided to simulate a realistic attacker perspective while enabling deeper security analysis.
The assessment should focus on:
* Authentication & Authorization testing (role escalation, privilege bypass, brute-force, MFA validation)
* Input Validation vulnerabilities (SQL Injection, XSS, command injection, insecure file upload, etc.)
* Session Management testing (session fixation, cookie security, token handling, logout functionality, idle timeout)
The testing methodology should follow OWASP Top 10 and industry-standard penetration testing practices. Automated tools may be used for discovery, but all findings must be manually verified to eliminate false positives.
Preferred tools and techniques:
* Burp Suite
* OWASP ZAP
* Nmap
* Nikto
* SQLmap
* Nuclei
* Manual testing and verification
Expected Deliverables:
1. Executive summary outlining overall security posture
2. Detailed technical report with:
* Vulnerability description
* CVSS severity rating
* Reproduction steps
* Screenshots/PoC
* Remediation recommendations
3. Severity-based vulnerability matrix
4. One retest after remediation with updated findings
5. Responsible handling and secure disposal of any sensitive data collected during testing
The final report should be delivered in both PDF and editable format within the agreed timeline.