OWASP Black-Box Web Pentest
Budget: €100 – €250 EUR
My website needs a thorough black-box penetration test with clear alignment to the OWASP Top 10. Parts of the application sit behind authentication, so once testing begins I will supply credentials for four distinct roles—Admin, Regular user, Guest user and Moderator user—to ensure privilege-related issues are uncovered.
Key functionality to scrutinise:
• User account management flows (registration, login, profile edits, password resets)
• Content management areas where users create, edit or publish items
Please probe both the public surface and the authenticated zones, watching for injection, XSS, broken access control, insecure deserialisation, misconfiguration and any other Top 10 category you can replicate. Automated scanning (Burp Suite, OWASP ZAP, etc.) is fine as long as manual verification follows; I need reproducible proof of each finding.
Deliverables
1. Executive summary highlighting business impact and risk ranking
2. Technical report detailing methodology, tools, evidence (screenshots / PoC), and remediation guidance for every issue
3. Risk-rated vulnerability matrix mapped to OWASP Top 10 categories
4. Retest memo once fixes are in place (optional but appreciated)
All testing must respect current legal boundaries and avoid disrupting production availability. If you foresee any high-load or destructive checks, flag them first so we can schedule a maintenance window.
Key functionality to scrutinise:
• User account management flows (registration, login, profile edits, password resets)
• Content management areas where users create, edit or publish items
Please probe both the public surface and the authenticated zones, watching for injection, XSS, broken access control, insecure deserialisation, misconfiguration and any other Top 10 category you can replicate. Automated scanning (Burp Suite, OWASP ZAP, etc.) is fine as long as manual verification follows; I need reproducible proof of each finding.
Deliverables
1. Executive summary highlighting business impact and risk ranking
2. Technical report detailing methodology, tools, evidence (screenshots / PoC), and remediation guidance for every issue
3. Risk-rated vulnerability matrix mapped to OWASP Top 10 categories
4. Retest memo once fixes are in place (optional but appreciated)
All testing must respect current legal boundaries and avoid disrupting production availability. If you foresee any high-load or destructive checks, flag them first so we can schedule a maintenance window.