Mobile App Penetration Testing

Job ID: 40513324

Budget: ₹12,500 – ₹37,500 INR

I want a full-scale penetration test carried out against my in-house mobile application suite, which is live on both iOS and Android. The goal is to uncover real-world attack paths, confirm their impact, and give my developers a crystal-clear remediation plan before our next public release.

Scope
• Assess the compiled apps as they stand in production, plus the traffic they generate with our back-end APIs.
• Cover the OWASP Mobile Top 10 and any platform-specific issues unique to iOS or Android (e.g., keychain misuse, insecure storage, WebView hijack, exported components).
• Test from the standpoint of an external attacker with no prior credentials; privilege-escalation paths up to an admin account should also be explored.

What I need from you
1. A concise testing methodology up front so I can align it with our internal compliance checklist.
2. Periodic progress updates if the engagement stretches beyond a single day.
3. A final report that includes:
– Executive summary written in plain English for leadership
– Technical findings with evidence (screenshots, code snippets, packet captures)
– Risk rating and reproducible PoC steps for every vulnerability
– Remediation advice that my development team can act on immediately

Acceptance criteria
• Every vulnerability is reproducible using the steps you provide.
• No production data is altered or destroyed during testing.
• The report is delivered in PDF within 48 hours after the live test window closes.

Experience with common mobile testing suites—Burp Suite, Frida, OWASP MSTG tools, or similar—will help you move quickly in our environment. If your approach differs, let me know up front so I can provision the right access.