Web App Penetration Testing

Job ID: 39858778

Budget: $150 – $300 USD

I need a seasoned security tester to put my web presence through its paces. The exact number of applications is still being finalised, but the scope will certainly cover both vulnerability discovery and deep checks for open ports, root-kits, and back-doors. Once issues are uncovered, I also want hands-on help deploying a Web Application Firewall and tuning Cloudflare’s Anti-DDoS protections.

My engagement is structured in two clear tiers so you can quote accordingly and so I can choose the depth that fits:

• Tier 1 – Baseline Security Review
– Automated and manual scans to spot common weaknesses
– Analysis of every finding with risk rating and remediation advice
– Port, root-kit, and back-door sweeps
– WAF and Cloudflare set-up assistance
– Concise executive report

• Tier 2 – Full Black-Box Simulation
– Real-world attack scenarios executed blind, following NIST, MITRE ATT&CK, and OWASP Top 10 guidance
– OSINT-driven reconnaissance and attack-surface mapping with SN1PER Professional
– Vulnerability assessment using Acunetix Business Pro and Burp Suite, followed by exploitation (SQLi, brute-force, XSS, RCE, LFI/RFI, CSRF, SSRF, etc.)
– Step-by-step proof-of-concept for each successful exploit and prioritised mitigation roadmap
– Final report suitable for both engineers and executives, plus follow-up support to close every gap

Please outline the tools and methodologies you intend to use, your past experience with similar engagements, and your estimated timeframe for each tier. I’m ready to move quickly once we align on scope and approach.