Web & API Penetration Test
Budget: $15 – $25 USD
I need an experienced security professional to carry out a thorough gray-box penetration test on both our public-facing website and its accompanying REST API. You will receive limited internal knowledge—network architecture diagrams and non-privileged user credentials—so you can replicate a realistic attacker with partial insight while still diving deep.
Scope
• Test the full web application stack (frontend, backend, database calls) and every exposed API endpoint.
• Use manual exploitation techniques alongside automated scanners where helpful; Burp Suite Pro, OWASP ZAP, Nmap, sqlmap, and any custom scripts you normally rely on are all welcome as long as findings are reproducible.
• Evaluate common OWASP Top 10 vectors as they arise, but please allow your methodology to surface any less obvious attack paths rather than restricting to a checklist.
Deliverables
1. A concise executive summary highlighting overall risk.
2. A detailed technical report for each confirmed vulnerability with: severity rating (CVSS), step-by-step reproduction, screenshots or request/response logs, and clear remediation guidance.
3. Proof-of-concept code or recorded evidence for critical findings.
4. A post-test debrief over video or voice to walk our dev team through results and answer questions.
Acceptance Criteria
• No automated tool-only results—each issue must be manually validated.
• False positives under 5 %.
• Reports delivered in both PDF and editable format (DOCX or Markdown).
• All testing activities must respect our provided rules of engagement and stay within the agreed IP ranges and accounts.
Timeline: Two weeks from kickoff to final report, with preliminary critical alerts sent to us within 24 hours of discovery.
If you have a proven track record performing gray-box tests on similar SaaS platforms or APIs, I’d love to review a brief summary of recent engagements and one sanitized sample report to gauge depth of analysis.
Scope
• Test the full web application stack (frontend, backend, database calls) and every exposed API endpoint.
• Use manual exploitation techniques alongside automated scanners where helpful; Burp Suite Pro, OWASP ZAP, Nmap, sqlmap, and any custom scripts you normally rely on are all welcome as long as findings are reproducible.
• Evaluate common OWASP Top 10 vectors as they arise, but please allow your methodology to surface any less obvious attack paths rather than restricting to a checklist.
Deliverables
1. A concise executive summary highlighting overall risk.
2. A detailed technical report for each confirmed vulnerability with: severity rating (CVSS), step-by-step reproduction, screenshots or request/response logs, and clear remediation guidance.
3. Proof-of-concept code or recorded evidence for critical findings.
4. A post-test debrief over video or voice to walk our dev team through results and answer questions.
Acceptance Criteria
• No automated tool-only results—each issue must be manually validated.
• False positives under 5 %.
• Reports delivered in both PDF and editable format (DOCX or Markdown).
• All testing activities must respect our provided rules of engagement and stay within the agreed IP ranges and accounts.
Timeline: Two weeks from kickoff to final report, with preliminary critical alerts sent to us within 24 hours of discovery.
If you have a proven track record performing gray-box tests on similar SaaS platforms or APIs, I’d love to review a brief summary of recent engagements and one sanitized sample report to gauge depth of analysis.
Related categories:
Web Security
Compliance
Penetration Testing
Network Security
Risk Assessment
Data Protection