Full Access Security Audit
Budget: ₹1,500 – ₹12,500 INR
I will be granting you complete credentials and architecture documentation so you can perform a thorough ethical security audit on everything we run—our public-facing web applications, the underlying network, and both iOS and Android builds.
Your job is to evaluate every component with a white-box mindset, replicate any weaknesses you discover, and explain how each issue can be fixed. Feel free to leverage the usual toolchain (Burp Suite, OWASP ZAP, Nmap, Metasploit, MobSF or anything similar) as well as manual techniques; depth of coverage matters more than the specific utilities you choose.
Deliverables
• Detailed technical report listing every vulnerability, its CVSS or comparable severity, reproducible steps, and screenshots or PoC scripts
• Executive-level summary that a non-technical stakeholder can understand
• Prioritized remediation roadmap with quick wins vs longer-term fixes
• Optional brief retest notes confirming patches, if time allows within the same engagement
Acceptance criteria
The engagement is complete when I can reproduce your findings exactly as documented and the report is clear enough for our internal developers and sysadmins to act on without additional clarification.
Your job is to evaluate every component with a white-box mindset, replicate any weaknesses you discover, and explain how each issue can be fixed. Feel free to leverage the usual toolchain (Burp Suite, OWASP ZAP, Nmap, Metasploit, MobSF or anything similar) as well as manual techniques; depth of coverage matters more than the specific utilities you choose.
Deliverables
• Detailed technical report listing every vulnerability, its CVSS or comparable severity, reproducible steps, and screenshots or PoC scripts
• Executive-level summary that a non-technical stakeholder can understand
• Prioritized remediation roadmap with quick wins vs longer-term fixes
• Optional brief retest notes confirming patches, if time allows within the same engagement
Acceptance criteria
The engagement is complete when I can reproduce your findings exactly as documented and the report is clear enough for our internal developers and sysadmins to act on without additional clarification.
Related categories:
Linux
Web Security
Mobile App Development
Android
Computer Security
Penetration Testing
Security
Network Security