web application pentest
Budget: $10 – $150 USD
I'm looking for an experienced penetration tester to conduct a comprehensive review of my web application. This should involve combining automated scans with manual attacks to cover real-world threat scenarios and deliver meaningful results.
Test Focus:
• Authentication issues – e.g., session handling, privilege escalation
• Data validation issues – injection, XSS, insecure deserialization
• Security configuration issues – missing headers, weak CORS policies, outdated components
• Targeted exploitation of known CVE vulnerabilities
What I Expect:
1. A brief kick-off meeting to discuss scope, test environment, and NDA.
2. Execution of automated scans (e.g., with Burp Suite, OWASP ZAP) and in-depth manual testing.
3. Demonstrable exploits with clear steps for reproduction in a secure environment.
4. Final report (PDF) in German or English, including:
– Risk assessment (CVSS), affected endpoints, proof-of-concept screenshots
– Specific recommendations for remediation and hardening
5. Final review to address any remaining questions.
The web application is available in a separate test environment with administrator access. If special tools, credentials, or VPN access are required, I will provide them upon request.
Please briefly describe your methodology (OWASP Top 10, PTES, etc.), relevant certifications (e.g., OSCP, CEH), and provide an example of previous reports. I look forward to your expertise so we can significantly improve the security of our application.
Test Focus:
• Authentication issues – e.g., session handling, privilege escalation
• Data validation issues – injection, XSS, insecure deserialization
• Security configuration issues – missing headers, weak CORS policies, outdated components
• Targeted exploitation of known CVE vulnerabilities
What I Expect:
1. A brief kick-off meeting to discuss scope, test environment, and NDA.
2. Execution of automated scans (e.g., with Burp Suite, OWASP ZAP) and in-depth manual testing.
3. Demonstrable exploits with clear steps for reproduction in a secure environment.
4. Final report (PDF) in German or English, including:
– Risk assessment (CVSS), affected endpoints, proof-of-concept screenshots
– Specific recommendations for remediation and hardening
5. Final review to address any remaining questions.
The web application is available in a separate test environment with administrator access. If special tools, credentials, or VPN access are required, I will provide them upon request.
Please briefly describe your methodology (OWASP Top 10, PTES, etc.), relevant certifications (e.g., OSCP, CEH), and provide an example of previous reports. I look forward to your expertise so we can significantly improve the security of our application.