Website Vulnerability Assessment Needed
Budget: ₹600 – ₹1,500 INR
My personal blog runs on a standard LAMP stack and I want a clear, ethical snapshot of its current security posture. The focus is on preventing data breaches and blocking any avenue for unauthorized access; malware checks are welcome but secondary.
Scope
You will carry out a legally authorised vulnerability assessment that covers:
• A surface scan of the domain and sub-domains, mapping open ports and exposed services.
• Manual and automated testing against the OWASP Top 10, using tools such as Burp Suite Community/Pro, OWASP ZAP, Nikto, or similar.
• SSL/TLS configuration review, confirming protocol versions, cipher strength, and certificate chain integrity.
• Inspection of server and application misconfigurations that could lead to privilege escalation, credential leakage, or unintended data exposure.
Reporting & Deliverables
1. A professionally formatted PDF report that:
– Lists every finding with CVSS or comparable risk rating.
– Explains potential impact in plain language.
– Provides step-by-step remediation guidance and references (best-practice links, config snippets, patch details).
2. A concise executive summary I can show non-technical stakeholders.
3. All raw scan logs in a separate archive for future verification.
Acceptance Criteria
• The assessment must be non-intrusive: no denial-of-service or destructive exploits.
• Testing is limited to the assets I authorise; any out-of-scope finding must be reported immediately.
• Draft report delivered within the agreed timeline, final version after my review of the findings.
There are no regulatory frameworks to satisfy (GDPR/HIPAA not applicable), so the focus can remain squarely on best-practice hardening. If your methodology aligns with standard penetration-testing guidelines and you can sign an NDA, I’m ready to grant you temporary access.
Scope
You will carry out a legally authorised vulnerability assessment that covers:
• A surface scan of the domain and sub-domains, mapping open ports and exposed services.
• Manual and automated testing against the OWASP Top 10, using tools such as Burp Suite Community/Pro, OWASP ZAP, Nikto, or similar.
• SSL/TLS configuration review, confirming protocol versions, cipher strength, and certificate chain integrity.
• Inspection of server and application misconfigurations that could lead to privilege escalation, credential leakage, or unintended data exposure.
Reporting & Deliverables
1. A professionally formatted PDF report that:
– Lists every finding with CVSS or comparable risk rating.
– Explains potential impact in plain language.
– Provides step-by-step remediation guidance and references (best-practice links, config snippets, patch details).
2. A concise executive summary I can show non-technical stakeholders.
3. All raw scan logs in a separate archive for future verification.
Acceptance Criteria
• The assessment must be non-intrusive: no denial-of-service or destructive exploits.
• Testing is limited to the assets I authorise; any out-of-scope finding must be reported immediately.
• Draft report delivered within the agreed timeline, final version after my review of the findings.
There are no regulatory frameworks to satisfy (GDPR/HIPAA not applicable), so the focus can remain squarely on best-practice hardening. If your methodology aligns with standard penetration-testing guidelines and you can sign an NDA, I’m ready to grant you temporary access.
Related categories:
Linux
Web Security
Computer Security
Internet Security
Penetration Testing
Network Security
Risk Assessment
LAMP