Secure Mobile App Penetration
Budget: ₹12,500 – ₹37,500 INR
I have a suite of customer-facing mobile apps and need a seasoned ethical hacker to put them through a full offensive security cycle, then guide me through hardening them. The assessment must concentrate solely on the mobile layer—both Android and iOS builds are in scope—and my highest priority is preventing data breaches.
Here’s the flow I envision: you start with reconnaissance and dynamic/static analysis, uncover every real-world exploit you can (OWASP MSTG, Burp Suite Mobile Assistant, Frida, and similar tools are welcome), and document proof-of-concept attacks. After we review the findings together, I’ll expect concise remediation steps and, where feasible, direct code or configuration fixes from you. Once patches are applied, you’ll run a final validation pass to confirm the vulnerabilities are fully closed and that a hardened security layer now sits between the apps and any backend services or third-party SDKs.
Deliverables
• Initial penetration report with risk-rated findings and reproducible steps
• Actionable remediation guide or implemented fixes (pull requests / configuration changes)
• Final verification report showing zero critical or high findings
Acceptance criteria: every critical or high-severity issue identified in the first report must be demonstrably resolved, and sensitive data should never be exposed at rest or in transit after hardening.
If this end-to-end cycle matches your expertise, let’s get started.
Here’s the flow I envision: you start with reconnaissance and dynamic/static analysis, uncover every real-world exploit you can (OWASP MSTG, Burp Suite Mobile Assistant, Frida, and similar tools are welcome), and document proof-of-concept attacks. After we review the findings together, I’ll expect concise remediation steps and, where feasible, direct code or configuration fixes from you. Once patches are applied, you’ll run a final validation pass to confirm the vulnerabilities are fully closed and that a hardened security layer now sits between the apps and any backend services or third-party SDKs.
Deliverables
• Initial penetration report with risk-rated findings and reproducible steps
• Actionable remediation guide or implemented fixes (pull requests / configuration changes)
• Final verification report showing zero critical or high findings
Acceptance criteria: every critical or high-severity issue identified in the first report must be demonstrably resolved, and sensitive data should never be exposed at rest or in transit after hardening.
If this end-to-end cycle matches your expertise, let’s get started.