Web & Mobile Application Security Audit
Budget: $250 – $750 USD
Comprehensive Audit (Most Popular)
Web Application Penetration Testing
A professional web application security audit (black-box analysis) is required.
- Identify vulnerabilities from the OWASP Top 10 list (SQLi, XSS, SSRF, etc.).
- Check authorization logic, session management, and access rights.
- Test API and file upload mechanisms.
**Result:**
A technical report with a detailed description of each vulnerability, screenshots (PoC), and clear recommendations for remediation.
**Timeframe:** [3-5 days].
**Budget:** [from $500 to $2,500].
Option 2: Mobile Application Audit
Mobile Application Security Audit (iOS/Android)
A mobile application needs to be tested for vulnerabilities and data leaks.
- Client-side security analysis (data storage, obfuscation).
- Backend security check (API Security).
- Search for opportunities to intercept data and bypass security mechanisms.
**Result:** A report on identified risks, prioritized (High/Medium/Low) and a step-by-step remediation plan.
Ready to provide the build and documentation after signing the application.
OSINT and Intelligence (Open Source Intelligence)
OSINT Research of the External Attack Surface
An audit of the company's external digital presence is required to identify potential attack vectors.
**Included in the work:**
- Search for forgotten subdomains, open ports, and databases.
- Analysis of corporate data leaks and employee accounts.
- Identification of vulnerabilities for phishing attacks or social engineering.
**Result:** A detailed dossier with an asset map and a list of critical threats that require immediate mitigation.
Quick Scan (Small Task)
Express Website Security Audit (2-3 days)
I need a quick scan of my website for critical vulnerabilities before launch.
I'm primarily interested in the most obvious vulnerabilities: exposed configuration files, default passwords, injections, and server configuration errors.
**Format:** A brief report with a list of "what to fix right now."
Red Teaming (Real Attack Simulation)
Infrastructure Attack Simulation (Red Teaming)
I need to conduct a controlled simulation of a real attacker's actions.
**Goal:** To test not only the security of my systems but also the response time of my team (SOC/admins).
**Scenario:** [specify, for example, "penetration of the internal network through phishing"].
Work strictly within the agreed-upon Rules of Engagement. Experience with similar projects is required.
Web Application Penetration Testing
A professional web application security audit (black-box analysis) is required.
- Identify vulnerabilities from the OWASP Top 10 list (SQLi, XSS, SSRF, etc.).
- Check authorization logic, session management, and access rights.
- Test API and file upload mechanisms.
**Result:**
A technical report with a detailed description of each vulnerability, screenshots (PoC), and clear recommendations for remediation.
**Timeframe:** [3-5 days].
**Budget:** [from $500 to $2,500].
Option 2: Mobile Application Audit
Mobile Application Security Audit (iOS/Android)
A mobile application needs to be tested for vulnerabilities and data leaks.
- Client-side security analysis (data storage, obfuscation).
- Backend security check (API Security).
- Search for opportunities to intercept data and bypass security mechanisms.
**Result:** A report on identified risks, prioritized (High/Medium/Low) and a step-by-step remediation plan.
Ready to provide the build and documentation after signing the application.
OSINT and Intelligence (Open Source Intelligence)
OSINT Research of the External Attack Surface
An audit of the company's external digital presence is required to identify potential attack vectors.
**Included in the work:**
- Search for forgotten subdomains, open ports, and databases.
- Analysis of corporate data leaks and employee accounts.
- Identification of vulnerabilities for phishing attacks or social engineering.
**Result:** A detailed dossier with an asset map and a list of critical threats that require immediate mitigation.
Quick Scan (Small Task)
Express Website Security Audit (2-3 days)
I need a quick scan of my website for critical vulnerabilities before launch.
I'm primarily interested in the most obvious vulnerabilities: exposed configuration files, default passwords, injections, and server configuration errors.
**Format:** A brief report with a list of "what to fix right now."
Red Teaming (Real Attack Simulation)
Infrastructure Attack Simulation (Red Teaming)
I need to conduct a controlled simulation of a real attacker's actions.
**Goal:** To test not only the security of my systems but also the response time of my team (SOC/admins).
**Scenario:** [specify, for example, "penetration of the internal network through phishing"].
Work strictly within the agreed-upon Rules of Engagement. Experience with similar projects is required.
Related categories:
Web Security
Android
Usability Testing
Internet Security
Penetration Testing
Risk Assessment
Data Protection
OSINT