Greybox Web Shop Pen Test
Budget: €30 – €250 EUR
I need a greybox penetration test on our staging web shop. The assessment must cover three critical user flows—payment gateway, registration/login, and the product catalog—so I can pinpoint real-world vulnerabilities before we push to production.
The single overriding goal is to identify weaknesses, with special attention to anything that could lead to Cross-Site Scripting (XSS), but all other findings are welcome. I will provide a standard customer account, limited backend documentation, and either a VPN tunnel or temporary public URL to the test environment, depending on your preference.
Please include in your delivery:
• An executive summary that’s readable for non-technical leadership.
• A detailed technical report for developers, mapping each issue to the OWASP Top 10, complete with proof-of-concept steps, screenshots, and raw request/response data.
• CVSS-based risk ratings and clear remediation guidance.
• One complimentary retest to verify fixes.
Automated scanners (Burp Suite Pro, OWASP ZAP, sqlmap, etc.) are fine.
The single overriding goal is to identify weaknesses, with special attention to anything that could lead to Cross-Site Scripting (XSS), but all other findings are welcome. I will provide a standard customer account, limited backend documentation, and either a VPN tunnel or temporary public URL to the test environment, depending on your preference.
Please include in your delivery:
• An executive summary that’s readable for non-technical leadership.
• A detailed technical report for developers, mapping each issue to the OWASP Top 10, complete with proof-of-concept steps, screenshots, and raw request/response data.
• CVSS-based risk ratings and clear remediation guidance.
• One complimentary retest to verify fixes.
Automated scanners (Burp Suite Pro, OWASP ZAP, sqlmap, etc.) are fine.