Mobile App Security Hardening
Budget: ₹600 – ₹1,500 INR
I need a cyber-security professional who specialises in application security to review and harden a production-ready mobile app that runs on both iOS and Android. The codebase has already passed functional QA; now I want to be certain it stands up to real-world attacks.
Scope
• Perform a full security assessment that covers the OWASP Mobile Top 10.
• Include static code analysis, dynamic runtime testing and API endpoint verification.
• Highlight insecure data storage, improper authentication flows, weak cryptography and any third-party library risks.
• Provide clear, reproducible proofs of concept for every confirmed vulnerability.
Deliverables
1. Written penetration-test report detailing findings, risk ratings and recommended fixes.
2. A prioritised remediation checklist I can hand directly to my development team.
3. A follow-up retest (once fixes are applied) to confirm all critical and high-risk issues are closed.
Acceptance Criteria
• Zero critical or high-risk findings remain after retest.
• Medium findings have documented mitigations or workarounds.
• All reports and artefacts are delivered in PDF and Markdown formats.
The project repository is hosted on GitHub and builds through CI/CD pipelines (Bitrise for iOS, GitHub Actions for Android). Please tell me which tools you prefer—Burp Suite, MobSF, Frida, etc.—and share a sample report if available so I can gauge the depth of your analysis.
Scope
• Perform a full security assessment that covers the OWASP Mobile Top 10.
• Include static code analysis, dynamic runtime testing and API endpoint verification.
• Highlight insecure data storage, improper authentication flows, weak cryptography and any third-party library risks.
• Provide clear, reproducible proofs of concept for every confirmed vulnerability.
Deliverables
1. Written penetration-test report detailing findings, risk ratings and recommended fixes.
2. A prioritised remediation checklist I can hand directly to my development team.
3. A follow-up retest (once fixes are applied) to confirm all critical and high-risk issues are closed.
Acceptance Criteria
• Zero critical or high-risk findings remain after retest.
• Medium findings have documented mitigations or workarounds.
• All reports and artefacts are delivered in PDF and Markdown formats.
The project repository is hosted on GitHub and builds through CI/CD pipelines (Bitrise for iOS, GitHub Actions for Android). Please tell me which tools you prefer—Burp Suite, MobSF, Frida, etc.—and share a sample report if available so I can gauge the depth of your analysis.
Related categories:
Mobile App Development
Android
Testing / QA
Computer Security
Cryptography
Risk Management
Penetration Testing