Snapnames SQL Injection Vulnerability Hunt
Budget: $10 – $11 USD
I need an experienced security tester to probe snapnames.com specifically for SQL Injection issues. Although we already run a Web Application Firewall, apply input-validation routines, and rely on parameterized queries, I suspect exploitable gaps may still exist.
Your focus should be the areas most likely to expose an injection point—our login forms, search functionality, and any other user-supplied input fields you can reach. Black-box techniques are fine as long as they remain non-destructive and within legal boundaries.
Deliverables
• A concise report detailing every confirmed SQL Injection finding, including the exact request/response pairs, database error messages (if any), and evidence that the payload reached the back-end.
• Clear, step-by-step reproduction instructions so my dev team can verify each issue.
• Recommended fixes for each vulnerability, mapped to the affected code path or parameter.
• A short executive summary that highlights overall risk and residual exposure after remediation.
I will provide test-account credentials and any additional endpoint documentation you need once we start.
Your focus should be the areas most likely to expose an injection point—our login forms, search functionality, and any other user-supplied input fields you can reach. Black-box techniques are fine as long as they remain non-destructive and within legal boundaries.
Deliverables
• A concise report detailing every confirmed SQL Injection finding, including the exact request/response pairs, database error messages (if any), and evidence that the payload reached the back-end.
• Clear, step-by-step reproduction instructions so my dev team can verify each issue.
• Recommended fixes for each vulnerability, mapped to the affected code path or parameter.
• A short executive summary that highlights overall risk and residual exposure after remediation.
I will provide test-account credentials and any additional endpoint documentation you need once we start.
Related categories:
Web Security
Penetration Testing
Network Security
Risk Assessment
Data Protection