Web App Testing

Job ID: 32013075

Budget: ₹1,500 – ₹12,500 INR

For the one/two page application lab:



The technical/reporting assessment will be in the form of a small vulnerable site with several common web application security issues. The goal is to find as many issues as possible and write a short, formal finding that describes the issue at both a technical and non-technical level.
We will provide a template for the reporting as well as an example finding to give you an idea of the amount of detail you may want to include. (attached)
You should perform a manual penetration test against a simple web application, the use of automated vulnerability scanners (such as Burp active scan) is not permitted.
The web application is the only item in scope, additional port scanning is not required. The goal of this part of the interview process is to evaluate your ability to identity and communicate common vulnerabilities as well as test your time management skills. As such, please ensure that you send your final version of the report once the testing window has closed. Try to use your own words as much as possible and contextualise the findings to the application under test.
The application will be available at the following URL based on the previously agreed time:
http://ukccxrecruittest-env.eba-qmjdvkpp.us-east-2.elasticbeanstalk.com/
No brute forcing of filenames etc is required - you can access the login interface using the username “test” and the password “test”.
Note that the assessment can be performed remotely. A risk matrix is provided at the end of the report template, you should use this when calculating the risk for each finding, based on your assessment of the issue’s potential consequence and its likelihood of exploitation.
Can you also ensure you write up the executive summary in a format you would normally present to a client.
Related categories: Penetration Testing