web application pentest

Job ID: 40281341

Budget: $10 – $150 USD

I'm looking for an experienced penetration tester to conduct a comprehensive review of my web application. This should involve combining automated scans with manual attacks to cover real-world threat scenarios and deliver meaningful results.

Test Focus:

• Authentication issues – e.g., session handling, privilege escalation

• Data validation issues – injection, XSS, insecure deserialization

• Security configuration issues – missing headers, weak CORS policies, outdated components

• Targeted exploitation of known CVE vulnerabilities

What I Expect:

1. A brief kick-off meeting to discuss scope, test environment, and NDA.

2. Execution of automated scans (e.g., with Burp Suite, OWASP ZAP) and in-depth manual testing.

3. Demonstrable exploits with clear steps for reproduction in a secure environment.

4. Final report (PDF) in German or English, including:

– Risk assessment (CVSS), affected endpoints, proof-of-concept screenshots

– Specific recommendations for remediation and hardening

5. Final review to address any remaining questions.

The web application is available in a separate test environment with administrator access. If special tools, credentials, or VPN access are required, I will provide them upon request.

Please briefly describe your methodology (OWASP Top 10, PTES, etc.), relevant certifications (e.g., OSCP, CEH), and provide an example of previous reports. I look forward to your expertise so we can significantly improve the security of our application.