OWASP Web App Penetration Test
Budget: €30 – €250 EUR
I need a full black-box penetration test of my production site, https://hvhesp.sergioeh.dev. The goal is to measure how well the current security defenses stand up against real-world attacks while staying aligned with the OWASP Top 10 risks.
Environment details
• Front end: React + Vite
• Reverse proxy: Nginx
• Live data: Production database has been fully backed up, so you are free to test against the active environment.
Scope and priorities
Authentication and authorization flows, all data input/output validation, and session management must receive special attention. I will supply a valid username-and-password account so you can assess both unauthenticated and authenticated areas of the app.
Required deliverables
• Comprehensive report outlining each finding, its risk rating, proof of concept, and clear remediation guidance
• Executive summary that a non-technical stakeholder can understand
• Methodology mapped to the OWASP Top 10 and any additional frameworks or tools you employed (e.g., Burp Suite, OWASP ZAP, Nmap)
• Retest notes or confirmation steps so I can verify fixes later
Acceptance criteria
• No disruption of normal service for other users
• All high- or critical-risk issues include reproducible steps and screenshots
• Report delivered in PDF and editable format within the agreed timeline
Provide your estimated timeline and the main tools you plan to use, and we can get started right away.
Environment details
• Front end: React + Vite
• Reverse proxy: Nginx
• Live data: Production database has been fully backed up, so you are free to test against the active environment.
Scope and priorities
Authentication and authorization flows, all data input/output validation, and session management must receive special attention. I will supply a valid username-and-password account so you can assess both unauthenticated and authenticated areas of the app.
Required deliverables
• Comprehensive report outlining each finding, its risk rating, proof of concept, and clear remediation guidance
• Executive summary that a non-technical stakeholder can understand
• Methodology mapped to the OWASP Top 10 and any additional frameworks or tools you employed (e.g., Burp Suite, OWASP ZAP, Nmap)
• Retest notes or confirmation steps so I can verify fixes later
Acceptance criteria
• No disruption of normal service for other users
• All high- or critical-risk issues include reproducible steps and screenshots
• Report delivered in PDF and editable format within the agreed timeline
Provide your estimated timeline and the main tools you plan to use, and we can get started right away.
Related categories:
Linux
Web Security
Nginx
SQLite
Internet Security
React.js
Penetration Testing
Network Security
Vite
Security Auditing