OSINT Pentest on WASP and Infrastructure -- 2
Budget: $30 – $250 USD
I'm seeking a skilled pentester with OSINT expertise to conduct a security assessment of our web applications and infrastructure.
Key Responsibilities:
- Perform a thorough penetration test on our web applications.
Ideal Skills:
- Proficiency in web application security testing.
- Extensive experience in OSINT techniques.
- Familiarity with various pentesting tools.
timeline to deliver all requirements within 7 days while maintaining high-quality standards. Below is the detailed plan:
Timeline (7 Days)
Day 1: Initial Assessment and Setup
Review the existing intranet and network environment.
Identify gaps in access control and security.
Set up the Docker/VM environment for Red/Blue team configurations.
Day 2-3: Access Control and SSO Implementation
Integrate Single Sign-On (SSO) for secure and streamlined authentication.
Implement role-based access control mechanisms.
Test and validate SSO functionality for different user roles.
Day 4-5: Red/Blue Team Setup and Penetration Testing
Set up Red/Blue team configurations using VM/Docker to simulate attack/defense scenarios.
Perform penetration testing on the application and network using Linux/WSL2.
Day 6: Network Monitoring Setup
Deploy and configure network monitoring tools for real-time traffic analysis and threat detection.
Address any security issues identified during penetration testing.
Day 7: Final Testing, Documentation, and Handover
Conduct thorough end-to-end testing of all implemented solutions.
Prepare and deliver comprehensive project documentation and guides.
Handover and provide post-deployment support.
Deliverables
Fully configured Docker environment with integrated SSO.
Red/Blue team setup documentation and configuration files.
Penetration testing report with remediation steps.
Network monitoring system deployed and operational.
Final project documentation and user guides.
Anyone who can do this via anydesk is most welcome:
my existing app is based on React, Flask, Posgresql and docker.
eventually, we will use our app to test. first, use my vmbox infra, use github to document, use SADT for code test and for vulnerabilities, then setup more for monitoring such as Wazuh, sysinternals etc. then create a playbook and implement it
Key Responsibilities:
- Perform a thorough penetration test on our web applications.
Ideal Skills:
- Proficiency in web application security testing.
- Extensive experience in OSINT techniques.
- Familiarity with various pentesting tools.
timeline to deliver all requirements within 7 days while maintaining high-quality standards. Below is the detailed plan:
Timeline (7 Days)
Day 1: Initial Assessment and Setup
Review the existing intranet and network environment.
Identify gaps in access control and security.
Set up the Docker/VM environment for Red/Blue team configurations.
Day 2-3: Access Control and SSO Implementation
Integrate Single Sign-On (SSO) for secure and streamlined authentication.
Implement role-based access control mechanisms.
Test and validate SSO functionality for different user roles.
Day 4-5: Red/Blue Team Setup and Penetration Testing
Set up Red/Blue team configurations using VM/Docker to simulate attack/defense scenarios.
Perform penetration testing on the application and network using Linux/WSL2.
Day 6: Network Monitoring Setup
Deploy and configure network monitoring tools for real-time traffic analysis and threat detection.
Address any security issues identified during penetration testing.
Day 7: Final Testing, Documentation, and Handover
Conduct thorough end-to-end testing of all implemented solutions.
Prepare and deliver comprehensive project documentation and guides.
Handover and provide post-deployment support.
Deliverables
Fully configured Docker environment with integrated SSO.
Red/Blue team setup documentation and configuration files.
Penetration testing report with remediation steps.
Network monitoring system deployed and operational.
Final project documentation and user guides.
Anyone who can do this via anydesk is most welcome:
my existing app is based on React, Flask, Posgresql and docker.
eventually, we will use our app to test. first, use my vmbox infra, use github to document, use SADT for code test and for vulnerabilities, then setup more for monitoring such as Wazuh, sysinternals etc. then create a playbook and implement it