Web App Session Pentest

Job ID: 40240204

Budget: $750 – $1,500 USD

I’m looking for a seasoned penetration tester to perform a focused security assessment on our live SaaS web application. The scope is firmly set on web application pentesting, zeroing in on session management. Your mission is to uncover and demonstrate any weaknesses that could enable session hijacking or cross-site request forgery (CSRF).

You’ll work against a production-like staging instance with a demo user account I provide. A black-box approach is fine, but authenticated testing is mandatory so you can probe cookie handling, token rotation, SameSite settings, and logout logic. Feel free to wield Burp Suite, OWASP ZAP, or comparable tooling as long as your methodology aligns with the OWASP Testing Guide and PTES best practices.

Deliverables
• Executive summary outlining overall risk and business impact
• Detailed technical report listing every finding with: affected endpoints, impact analysis, CVSS score, reproducible proof-of-concept, and clear remediation guidance
• Screenshot or short video PoC for any critical or high findings
• One round of re-testing to verify fixes

Let me know your projected timeline, any preferred testing window, and the data you’ll need up front (headers, creds, etc.). Once we agree on scope and rules of engagement, I’ll provide access and a point of contact for real-time questions.