Web App Penetration Test & Report

Job ID: 40581894

Budget: $250 – $750 USD

I need a seasoned web-application security tester to run a full black-box assessment against xtracker.com. The engagement must align with the OWASP Top 10 and place extra scrutiny on three areas that matter most to me right now—authentication mechanisms, data-input validation, and session management.

Work as though you have zero internal knowledge: enumerate, probe, and exploit like an external attacker would, then translate everything you discover into clear, business-focused language I can act on quickly.

Deliverables
• Executive summary that ranks each finding by risk and business impact, with concise, step-by-step remediation advice
• Evidence for each vulnerability (screenshots, PoCs, request/response pairs) kept in an appendix so my developers can reproduce the issue
• Verification checklist showing which OWASP Top 10 items were tested and how
• Debrief call to walk through the findings and answer follow-up questions

You are free to use industry-standard tooling such as Burp Suite, OWASP ZAP, Nmap, or custom scripts—whatever gives you the best coverage—as long as the test remains non-disruptive and within the authorized scope.

I manage several sites, so a solid, actionable report and a professional approach on this project could lead to regular vulnerability-assessment work.