Web App Penetration Test Needed
Budget: ₹600 – ₹1,500 INR
I need an experienced ethical hacker to run a full-scope penetration test against our production web application. The sole objective is to discover and document real-world attack paths before they are exploited, so I can fix them quickly and prove due diligence to management.
I expect you to combine automated scanning with hands-on techniques, following industry standards such as OWASP and using tools you are comfortable with (Burp Suite, OWASP ZAP, custom scripts, etc.). The application is live, so the test must be non-destructive, respect user data, and take place during an agreed maintenance window.
Deliverables I’m looking for:
• A clear executive summary that highlights critical risks in plain language.
• A technical report detailing each finding, its risk rating, reproducible proof-of-concept steps, and specific remediation advice.
• A short follow-up retest once fixes are applied to confirm the issues are closed.
Please outline your methodology, estimated timeframe, and any required access in your proposal. Strong communication, confidentiality, and prior web application pentest experience are essential.
I expect you to combine automated scanning with hands-on techniques, following industry standards such as OWASP and using tools you are comfortable with (Burp Suite, OWASP ZAP, custom scripts, etc.). The application is live, so the test must be non-destructive, respect user data, and take place during an agreed maintenance window.
Deliverables I’m looking for:
• A clear executive summary that highlights critical risks in plain language.
• A technical report detailing each finding, its risk rating, reproducible proof-of-concept steps, and specific remediation advice.
• A short follow-up retest once fixes are applied to confirm the issues are closed.
Please outline your methodology, estimated timeframe, and any required access in your proposal. Strong communication, confidentiality, and prior web application pentest experience are essential.