BLE Device PENTEST
Budget: $10 – $30 USD
I have a proprietary Bluetooth Low Energy device reaching its final development milestone and I need a seasoned security specialist to put it through a full-scale assessment. The scope is tightly focused on two areas firmware security and the communication protocols so there is no hardware tampering or side-channel work required.
You will carry out a vulnerability assessment, an in-depth penetration test, and a top-to-bottom security audit, all mapped to the OWASP IoT Top Ten guidelines. I expect practical exploitation where possible, not just a checklist review.
Acceptable deliverables
• A concise test plan outlining tooling, coverage and timeline before work starts
• Raw findings as they emerge (packet captures, exploit scripts, screenshots,, etc.)
• A final report that includes an executive summary for management, detailed technical write-up, clear risk ratings, and remediation guidance
• One round of follow-up testing after fixes to confirm the vulnerabilities are closed
Experience with BLE sniffing (e.g., Ubertooth, Nordic nRF Sniffer), protocol fuzzing, and firmware reverse-engineering will be critical. All testing must be performed legally and ethically; I will supply the device, documentation, and written authorization.
If you have a proven track record in BLE or IoT security and can commit to fast, well-documented results, I’m ready to get started.
You will carry out a vulnerability assessment, an in-depth penetration test, and a top-to-bottom security audit, all mapped to the OWASP IoT Top Ten guidelines. I expect practical exploitation where possible, not just a checklist review.
Acceptable deliverables
• A concise test plan outlining tooling, coverage and timeline before work starts
• Raw findings as they emerge (packet captures, exploit scripts, screenshots,, etc.)
• A final report that includes an executive summary for management, detailed technical write-up, clear risk ratings, and remediation guidance
• One round of follow-up testing after fixes to confirm the vulnerabilities are closed
Experience with BLE sniffing (e.g., Ubertooth, Nordic nRF Sniffer), protocol fuzzing, and firmware reverse-engineering will be critical. All testing must be performed legally and ethically; I will supply the device, documentation, and written authorization.
If you have a proven track record in BLE or IoT security and can commit to fast, well-documented results, I’m ready to get started.