Top-Tier Web Penetration Test

Job ID: 40044846

Budget: ₹2,500 – ₹0 INR

I need an experienced security professional to carry out a full-scope penetration test against my production web application. The goal is to probe every layer that touches user authentication and the way we store or transmit data, then provide me with actionable evidence of weaknesses and clear remediation steps.

Scope
• The engagement centres on web application penetration testing—no network, wireless or social-engineering components at this stage.
• Priority attack surfaces include the login flow, session management, password reset, access-control logic, and any point where sensitive data is processed or stored. API endpoints are out of scope unless they directly affect the above components.

Approach
You are free to use industry-standard tooling such as Burp Suite, OWASP ZAP, SQLMap, Kali-based utilities or custom scripts, provided all findings can be reproduced in my staging environment. Testing must comply with OWASP Testing Guide and avoid any interruption of live service.

Deliverables
- Kick-off call to clarify targets, rules of engagement and timetable
- Written test plan outlining methodology and tooling
- Exploitation evidence: screenshots, request/response pairs, or short PoC scripts
- Risk-rated report covering each vulnerability, its impact, likelihood and remediation path
- Executive-level summary suitable for non-technical stakeholders
- Optional retest after fixes to confirm closure

Acceptance Criteria
A report that maps vulnerabilities to OWASP Top Ten categories and contains at least one validated finding for each in-scope area, or written confirmation that none were discovered, will mark the job complete.

Estimated start: as soon as NDA is in place. Clear communication and respect for safe-testing windows are essential.