Website Session Security Testing

Job ID: 39781766

Budget: $1,500 – $3,000 USD

I need an experienced bug-hunter or penetration tester to focus exclusively on the session layer of my production site. Please concentrate on the Regular User journey and probe for the three issues that worry me most: Session Fixation, Session Hijacking, and Cross-Site Request Forgery (CSRF).

Scope
• Live, authenticated workflows available to a standard user account (credentials will be supplied once we start).
• All browsers and devices that the average visitor is likely to use.
• No admin or guest areas are in scope for now.

Deliverables
1. A concise report that lists each confirmed vulnerability, the exact request/response pairs or PoCs, and clear reproduction steps.
2. Impact assessment plus practical mitigation or patch advice.
3. Screenshots, Burp Suite/OWASP ZAP logs, or similar evidence supporting every finding.

Kindly respect rate-limiting and uptime; all tests must avoid DoS-style flooding. Let me know your estimated timeline and the tools you prefer so we can coordinate access and testing windows.