Web App Front-End Penetration Test
Budget: €8 – €30 EUR
Our customer-facing web application is ready for a security health-check before we move to production. I need a thorough, hands-on penetration test focused strictly on the front-end layer and aligned with the OWASP Top 10.
Scope
Please probe the following surfaces and report every exploitable weakness you discover:
• Login / authentication workflow
• Data-entry forms (client-side validation, hidden fields, tampering)
• API interactions initiated from the browser, including token handling and CORS settings
Deliverables
1. A detailed vulnerability report that ranks findings by severity, maps each item to the relevant OWASP Top 10 category, and includes clear proof-of-concept steps.
2. Practical remediation guidance our dev team can action immediately.
3. A brief re-test summary once fixes are applied (optional but appreciated).
The application is built with standard modern tooling—React on the front end, RESTful JSON APIs—and is already running in a staging environment you can access via VPN.
Feel free to use Burp Suite, OWASP ZAP, or any equivalent toolkit; just tell me what you plan to use so we can whitelist the traffic. Testing windows are flexible, but I’d like the initial report within one week of access.
Scope
Please probe the following surfaces and report every exploitable weakness you discover:
• Login / authentication workflow
• Data-entry forms (client-side validation, hidden fields, tampering)
• API interactions initiated from the browser, including token handling and CORS settings
Deliverables
1. A detailed vulnerability report that ranks findings by severity, maps each item to the relevant OWASP Top 10 category, and includes clear proof-of-concept steps.
2. Practical remediation guidance our dev team can action immediately.
3. A brief re-test summary once fixes are applied (optional but appreciated).
The application is built with standard modern tooling—React on the front end, RESTful JSON APIs—and is already running in a staging environment you can access via VPN.
Feel free to use Burp Suite, OWASP ZAP, or any equivalent toolkit; just tell me what you plan to use so we can whitelist the traffic. Testing windows are flexible, but I’d like the initial report within one week of access.