
Open
Posted
•
Ends in 2 days
I an experienced penetration tester to web application. The primary objective is to identify vulnerabilities, with particular attention paid to three high-risk zones: • Authentication and authorization logic • Database exposure paths (SQL injection, insecure queries, weak configuration) • Input validation and handling that could open the door to XSS, command injection, or similar issues I will provide you with staging and live URLs, test accounts, and any required API keys. Please treat the exercise as a real-world black/grey-box engagement—no source code will be shared. You may use industry-standard tooling such as Burp Suite, OWASP ZAP, sqlmap, or custom scripts as you see fit, as long as methodology aligns with the OWASP Testing Guide.
Project ID: 40625358
26 proposals
Open for bidding
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
26 freelancers are bidding on average ₹937 INR/hour for this job

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
₹750 INR in 40 days
6.4
6.4

Hi, I can help you perform a comprehensive black/grey-box penetration test of your production web application while ensuring the assessment remains safe, non-disruptive, and within the agreed scope. With 16+ years of experience in cybersecurity and application security, I have conducted security assessments for SaaS platforms, enterprise web applications, and APIs. My testing methodology follows the OWASP Web Security Testing Guide and covers authentication, authorization, session management, SQL Injection, XSS, command injection, IDOR, CSRF, SSRF, file upload security, business logic flaws, and other OWASP Top 10 risks. Deliverables include: • Executive summary with overall risk assessment • Detailed technical report with CVSS severity ratings • Proof-of-concept evidence and reproducible steps • Prioritized remediation recommendations I use industry-standard tools including Burp Suite Professional, OWASP ZAP, Nmap, sqlmap, Metasploit, and custom testing scripts where appropriate. I can begin immediately after receiving the test URLs, accounts, API keys, and signed authorization. All testing will be conducted ethically, confidentially, and without impacting production availability. I look forward to helping you strengthen the security of your application. Best regards, SaD
₹1,000 INR in 40 days
5.3
5.3

Hello I am certified Ethical Hacker and Certified with Digital Forensics with 9 years of industry experience in the domain of Penetration testing of web, Mobile and network applications as well court admissible digital forensics investigation and reporting. I can conduct comprehensive penetration tests on your web application following the security benchmark of OWASP TOP 10 and SANS 25 Security benchmark, and specially efforts will be given to Authentication and authorization logic, SQL injection, insecure queries, weak configuration, Input validation and handling that could open the door to XSS, command injection. Detailed industry grade VAPT report would be provided along with practical recommendations. Regards Kajal Majhi
₹1,000 INR in 40 days
5.3
5.3

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive black/grey-box penetration test of your web application to identify and validate real-world vulnerabilities. Scope • Authentication & authorization testing (RBAC, privilege escalation, session management) • Database security assessment (SQL Injection, insecure queries, configuration weaknesses) • Input validation testing (XSS, command injection, SSRF, file upload, and related OWASP Top 10 issues) • API security and business logic testing where applicable Methodology & Tools • Testing aligned with the OWASP Web Security Testing Guide and PTES • Manual + automated assessment using Burp Suite, OWASP ZAP, SQLMap, Nmap, Nuclei, and custom scripts • Every finding is manually verified to eliminate false positives Deliverables • Executive Summary for stakeholders • Detailed VAPT report with CVSS severity ratings • PoC evidence, reproduction steps, and remediation guidance • Optional remediation retest after fixes We have extensive experience securing SaaS, fintech, healthcare, e-commerce, and enterprise web applications and can begin immediately once the URLs, test accounts, and scope are shared.
₹1,000 INR in 40 days
3.6
3.6

Hi there, Hope you are doing well I'd love to assist with your Web Application Penetration Testing. Our team has experience performing black-box and grey-box security assessments for web applications, focusing on identifying critical vulnerabilities before they reach production. We'll conduct a comprehensive security assessment following the OWASP Testing Guide, with special attention to authentication & authorization, SQL Injection, database exposure, XSS, command injection, insecure input validation, session management, and API security. Using industry-standard tools such as Burp Suite Professional, OWASP ZAP, sqlmap, and custom testing scripts, we'll thoroughly evaluate your staging and live environments. What You'll Receive Comprehensive web application penetration testing Vulnerability assessment with risk classification (Critical, High, Medium, Low) Proof of Concept (PoC) for validated vulnerabilities Detailed remediation recommendations with best practices Executive summary and technical security report Re-testing support after fixes (if required) I'd be happy to discuss the project scope, timeline, and testing methodology in more detail. Looking forward to working with you. Thanks & Regards, Dheeraj K.
₹1,000 INR in 40 days
3.1
3.1

Hi, I have gone through your Web App Vulnerability Pentest project. It looks straightforward at first, but details such as testing scope, authorization, authentication flows, and data protection requirements can cause issues later. I can outline a practical approach covering security auditing, XSS and vulnerability testing, risk assessment, compliance, and clear remediation guidance. I have over 10 years of experience in web security, penetration testing, network security, compliance, data protection, incident response, and risk assessment, and I'm excited to be part of your project. For more information about my background, feel free to check my profile: https://www.freelancer.com/u/microlent Let's discuss your web app, testing scope, and reporting requirements in the chat so I can recommend the most practical and cost-effective solution. ~ Rajesh
₹1,000 INR in 40 days
0.0
0.0

We've recently helped a client secure their web application by identifying and addressing critical vulnerabilities. We will assist in ensuring your production web application is fortified against potential threats while providing a thorough assessment of its security posture. I noted your focus on high-risk areas like authentication and authorization logic, database exposure paths, and input validation. Our approach will prioritize a clean and professional assessment that meets your specific needs. With extensive experience in penetration testing, we utilize industry-standard tools like Burp Suite and OWASP ZAP, ensuring our methodology aligns with the OWASP Testing Guide. We have numerous 5-star reviews on similar projects. It would be our privilege to help you with your project, and choosing us will be a decision you won't regret. Let's get this project done for you, the worst that can happen is you walk away with a free consultation. Regards, Henco Burger.
₹950 INR in 7 days
0.0
0.0

This project immediately caught my attention because it is exactly the type of work I do best. Your focus on a thorough assessment of authentication and authorization logic, database exposure paths, and input validation aligns perfectly with my skills in identifying vulnerabilities. I understand the importance of a clean, professional, and user-friendly report that provides seamless remediation advice. While I am new to freelancer, I have tons of experience and have done other projects off site, including extensive penetration testing using tools like Burp Suite and OWASP ZAP. I am committed to delivering a detailed technical report and a concise executive summary that meets your needs. If this sounds like what you're looking for I'd love to hear more about your project. Regards, Warrick Van Eeden
₹750 INR in 7 days
0.0
0.0

Hello, I am a Cybersecurity graduate with hands-on experience in Linux, networking, Python, and web application security fundamentals. I have worked on Django-based web applications and am familiar with OWASP Top 10 vulnerabilities, including SQL Injection, XSS, authentication flaws, and input validation issues. I can perform a structured security assessment using tools such as OWASP ZAP, Burp Suite (Community Edition), Nmap, and SQLMap where appropriate. I will provide a clear report with identified vulnerabilities, supporting evidence, risk ratings, and practical remediation recommendations. I am detail-oriented, committed to responsible testing, and maintain strict confidentiality throughout the engagement. I would appreciate the opportunity to work on your project and deliver a thorough assessment within the agreed timeline. Thank you for your consideration.
₹1,000 INR in 40 days
0.0
0.0

I'm an experienced Penetration Tester with expertise in black-box and grey-box web application security assessments. Your project aligns well with my experience. I will conduct a comprehensive assessment following the OWASP Web Security Testing Guide, focusing on authentication and authorization, SQL injection, database exposure, input validation, XSS, command injection, business logic flaws, and other critical vulnerabilities. Testing will combine manual techniques with industry-standard tools such as Burp Suite Professional, OWASP ZAP, sqlmap, Nmap, and custom scripts to ensure accurate results with minimal false positives. You'll receive a professional report containing an executive summary, detailed technical findings with CVSS scores, proof-of-concept evidence, and practical remediation recommendations. I also offer re-testing after fixes and can walk you through the critical findings in a follow-up call or chat. I strictly adhere to the authorized scope, maintain complete confidentiality, and can start the assessment immediately.
₹900 INR in 40 days
0.0
0.0

Hi I can perform a comprehensive black/grey-box penetration test following the OWASP Testing Guide, focusing on authentication, authorization, SQL injection, XSS, insecure input handling, API security, session management, and privilege escalation. Using tools like Burp Suite, OWASP ZAP, sqlmap, Nmap, and custom testing scripts, I'll provide validated findings with risk ratings, PoC evidence, and actionable remediation steps. The assessment will be conducted within your authorized scope, maintaining strict confidentiality, and delivered with a detailed technical report, executive summary, and post-assessment walkthrough. Thanks, Kuldeep
₹1,000 INR in 40 days
0.0
0.0

Hi, I am an experienced security professional specializing in Vulnerability Assessment and Penetration Testing (VAPT) for web applications, APIs, and browser extensions experiece more than 15 years. My focus is on identifying exploitable weaknesses, validating risks, and providing actionable remediation guidance aligned with industry standards such as OWASP Top 10, SANS CWE, and NIST guidelines.
₹1,000 INR in 40 days
0.0
0.0

Hello, I'd be happy to help assess the security of your web application. I'm a web penetration tester and active bug bounty hunter with hands-on experience finding and responsibly reporting vulnerabilities in real-world applications. My approach combines manual testing with tools like Burp Suite, Nmap, sqlmap (when appropriate), ffuf, and custom scripts. I focus on identifying high-impact issues such as broken authentication, access control flaws, SQL injection, XSS, command injection, business logic vulnerabilities, and API security weaknesses that automated scanners often miss. For your engagement, I will thoroughly assess the authentication and authorization logic, database exposure paths, input validation, and other critical attack surfaces while strictly staying within the agreed scope. Every confirmed finding will be manually verified to eliminate false positives. You'll receive a professional report including an executive summary, detailed technical findings, CVSS severity ratings, proof-of-concept evidence, reproduction steps, and practical remediation recommendations. I'm also happy to walk you through the results in a follow-up call or chat and answer any questions. I understand the importance of confidentiality and responsible testing, and I will treat your application and data with the highest level of professionalism. I look forward to helping improve the security of your application. Thank you for your consideration.
₹1,100 INR in 40 days
0.0
0.0

with around 4 years of experience in Cyber security I focus on multiple domains like web,mobile, api and network and tested 400+ application with industry recognized certificate like OSCP+, OSCP, CEH, CRTA and CPTE. which makes me ideal candidate. I am Faizad, a cybersecurity specialist, and penetration tester par excellence. With a focus on multiple domains such as web, mobile, API and network security along with my expertise in ethical hacking and VAPT, I have amassed over 4 years of rich experience. During this time, I have successfully conducted vulnerability assessments for more than 400 applications using various cutting-edge tools like Burp Suite, OWASP ZAP, sqlmap and custom scripts built by me. As you've rightly stressed on particular high-risk zones for this project; authentication and authorization logic, database exposure paths and input validation and handling, I'd like to highlight that I'm well versed in the methodologies prescribed by OWASP Testing Guide which will ensure systematic vulnerability identification across these areas. Moreover, holding industry recognized certificates like OSCP+, OSCP, CEH, CRTA and CPTE coupled with past experiences of securing web applications giving utmost priority to data privacy make me the ideal choice. Feel confident with me as your partner in exposing any potential vulnerabilities in your web app while adhering strictly to the ethics governing our field. Let's neutralize any threats together!
₹1,000 INR in 40 days
0.0
0.0

Hello, I am a Web Application Penetration Tester with hands-on experience identifying and validating security vulnerabilities in production and staging environments. I can perform a comprehensive black-box/grey-box security assessment following the OWASP Web Security Testing Guide and industry best practices. For this engagement, I will focus on: * Authentication & authorization flaws (Broken Access Control, IDOR, privilege escalation, session management) * SQL Injection and database exposure paths * Cross-Site Scripting (Stored, Reflected, DOM-based) * Command Injection, SSTI, LFI/RFI, Path Traversal * Input validation and business logic issues * API security testing (if applicable) * Security headers, cookies, and configuration review My testing methodology includes manual verification alongside tools such as Burp Suite Professional/Community, OWASP ZAP, sqlmap, Nmap, and custom testing scripts where appropriate. Every finding will be manually validated to minimize false positives. You will receive: * A professional penetration testing report * Risk ratings (CVSS/OWASP) * Clear proof-of-concept steps * Impact assessment * Practical remediation recommendations * Optional re-testing after fixes I understand the importance of responsible testing and will strictly follow the agreed scope while maintaining confidentiality throughout the engagement. I would be happy to discuss your requirements before starting. Thank you.
₹1,000 INR in 40 days
0.0
0.0

Hi, I'm an OSCP, CEH, and eJPT certified penetration tester with hands-on experience testing web applications following the OWASP Testing Guide, and I can start on your engagement right away. For this project, I'll focus on the three high-risk areas you mentioned: Authentication & Authorization: testing for broken access control, privilege escalation, session/token weaknesses Database Exposure: SQL injection, insecure queries, and misconfiguration checks Input Handling: XSS, command injection, and other input-based vulnerabilities I'll treat this as a real-world black/grey-box assessment using Burp Suite, OWASP ZAP, sqlmap, and manual exploitation techniques where needed — not just automated scans. My OSCP training especially helps in manually chaining vulnerabilities to demonstrate real business impact, not just surface-level findings. Deliverable: A detailed report with each vulnerability classified by severity (Critical/High/Medium/Low), proof-of-concept steps, and clear remediation recommendations — aligned with OWASP standards. I'm available to start as soon as you share the staging/live URLs and test credentials. Happy to hop on a quick call to discuss scope and timeline. Thanks, MD. AL-AMIN
₹750 INR in 40 days
0.0
0.0

OSCP-certified Penetration Tester with over 2 years of experience performing comprehensive security assessments for web applications, APIs, mobile applications (Android & iOS), and network environments. Skilled in identifying, validating, and reporting vulnerabilities aligned with the OWASP Top 10, API Security Top 10, and industry best practices. Experienced in manual penetration testing, security verification, vulnerability assessment, exploit validation, and delivering detailed remediation guidance. Proficient with tools such as Burp Suite, Nmap, Metasploit, Nessus, Wireshark, SQLMap, and OWASP ZAP. Committed to helping organizations strengthen their security posture through practical, risk-focused assessments and clear, actionable reporting.
₹800 INR in 40 days
0.0
0.0

Hi, I'm an OSCP-certified penetration tester experienced in black/grey-box web application assessments and would like to take this on. My methodology aligns directly with the OWASP Testing Guide and your three priority zones: 1. Authentication & authorization — session management flaws, privilege escalation, broken access control (IDOR), JWT/token weaknesses, and logic flaws around your provided test accounts. 2. Database exposure — SQL injection (manual + sqlmap-assisted), insecure query construction, and misconfigurations that could leak or expose data. 3. Input validation — XSS (reflected/stored/DOM), command injection, SSRF, and related injection classes across all input surfaces on staging and live URLs. Tooling: Burp Suite Pro for manual testing and traffic analysis, OWASP ZAP for automated coverage, sqlmap for injection validation, plus custom scripts where needed. No source code required — I'll treat this as a genuine external engagement. Deliverable: a prioritized report (CVSS-scored) with technical detail, business impact, and clear remediation guidance for each finding, plus a short walkthrough call if useful. I'll respect the scope you define (staging/live URLs, provided accounts, API keys) and flag anything destructive before touching it. Ready to start as soon as access is shared.
₹750 INR in 20 days
0.0
0.0

Hello, I can conduct a controlled external penetration test of your network and server infrastructure within the agreed maintenance window. I hold practical cybersecurity certifications including CPTS, CRTA, C3SA, CAP, and CNSP, with hands-on experience in network enumeration, vulnerability assessment, exploitation, Active Directory security, and risk reporting. Before testing, I will provide a clear scope and rules-of-engagement plan. The assessment will include Nmap-based reconnaissance, vulnerability validation with Nessus/OpenVAS, careful manual exploitation, and evidence collection without unnecessary service disruption. You will receive: • Prioritized technical and executive-level findings • Business impact and actionable remediation guidance • A debrief session covering each major issue • One complimentary retest of resolved critical findings I will only test approved systems and will immediately report any issue that could affect availability. Could you confirm the number of public IP addresses and whether VPN access will be provided for the server segment? Best regards, Momrul Hasan
₹1,000 INR in 40 days
0.0
0.0

Hello, I have solid experience in web application penetration testing and can perform a comprehensive black/grey-box security assessment following the OWASP Testing Guide and industry best practices. My testing approach will focus on the areas you’ve highlighted: * Authentication and authorization flaws (broken access control, privilege escalation, session management, IDOR, etc.) * Database security, including SQL injection, insecure queries, and configuration weaknesses * Input validation issues such as XSS, command injection, SSTI, file upload vulnerabilities, and other injection flaws I am comfortable working with staging and production environments using authorized test accounts and API keys. My toolkit includes Burp Suite Professional, OWASP ZAP, sqlmap, Nmap, and custom scripts where appropriate. The final deliverable will include: * Detailed vulnerability findings * Proof of Concept (PoC) for each issue * Risk severity assessment (CVSS where applicable) * Clear remediation recommendations * Retesting support after fixes, if required
₹750 INR in 40 days
0.0
0.0

Guntur, India
Member since Aug 4, 2026
$250-750 USD
$10-30 USD
$250-750 USD
₹750-1250 INR / hour
£20-250 GBP
$20-80 USD
$250-750 USD
$30-250 USD
$250-750 USD
$30-250 USD
$10-30 USD
$250-750 USD
$750-1500 USD
₹750-1250 INR / hour
₹12500-37500 INR
$250-750 USD
₹1500-12500 INR
₹600-1500 INR
₹12500-37500 INR
$10-30 USD