
Closed
Posted
Paid on delivery
I'm seeking an experienced security professional to conduct a web application penetration test. The main objective is to identify security vulnerabilities in the application. The scope of the test should include: - Authentication mechanisms - Data handling and storage - Session management Ideal candidates will have: - Proven experience in web application penetration testing - Strong understanding of authentication protocols, data security, and session management vulnerabilities - Relevant certifications (e.g., OSCP, CEH, or equivalent) - Ability to deliver a detailed report with identified vulnerabilities and remediation suggestions Please provide examples of previous work and relevant certifications.
Project ID: 40556789
57 proposals
Remote project
Active 20 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
57 freelancers are bidding on average €2,326 EUR for this job

Hi there, I'm Shofiur, CEO and Founder of Pentest Testing Corp. I'm a Certified Ethical Hacker who's spent years digging into authentication flows, session handling, and data storage across web apps for clients in 30+ countries. Here's how I'd approach your project. I'll start with recon to map out the app's attack surface, then dig into authentication (brute force resistance, password reset flaws, MFA bypass, weak JWT or session tokens), data handling (encryption gaps, exposed PII, injection points from poor input validation), and session management (fixation, predictable tokens, missing cookie flags, weak timeout logic). I test manually with Burp Suite against OWASP Top 10 and ASVS standards. Scanners catch the obvious stuff, but most real vulnerabilities live in business logic that only a human tester finds. Every issue I report gets a CVSS 3.1 score plus remediation steps your team can actually implement, not vague advice. You'll get an executive summary for stakeholders, full technical findings with proof of concept, and a free retest once fixes go live. I hold CEH along with specialized certifications in API penetration testing and PCI-focused API security. I can share redacted excerpts from past reports, client confidentiality always comes first. Happy to jump on a quick call to talk through scope and timeline. Best, Md Shofiur CEO & Founder, Pentest Testing Corp
€2,250 EUR in 7 days
7.4
7.4

As an IT expert with over 14 years of experience in managing server infrastructures, network security, and administration, I have developed a deep understanding of potential security vulnerabilities that could exist within web applications. My proficiency in working with both Windows and Linux-based server infrastructures is complemented by my credentials in handling some of the industry's renowned security products. Specifically, I am well-acquainted with various firewall solutions including Checkpoint, Cisco ASA, Palo Alto and Fortigate which provide an added advantage during penetration testing. In addition to my assurance to meet your technical requirements for this project, I also pride myself on providing thorough and timely deliverables. You'll also find my familiarity with important standards like CMMC, PCI DSS, HIPPA, ISO 27001, OWASP a valuable asset in ensuring your organization's compliance. By hiring me for this comprehensive web application pen test project, you are making a strategic decision to maximize the efficiency and efficacy of your site's ecosystem to keep it safe from external threats while staying compliant with industry regulations
€2,000 EUR in 7 days
6.6
6.6

Hi, I am jobyer, OSCE3(osed, osep, oswe), cissp, oscp, pentest+, security+, 12 years of experience holding multiple cves under my name. I will perform in depth security assessment and provide branded report with vulnerability details, PoC, recommendations. If you need to work sample please lets discuss Thanks
€3,000 EUR in 7 days
6.7
6.7

Hi! ----------------I have experience performing comprehensive web application penetration testing with a focus on authentication, session management, and data security, following industry-standard methodologies such as OWASP. I'll provide a detailed report outlining identified vulnerabilities, their risk levels, proof of findings, and practical remediation recommendations. ------------------------------------------------------- Question: Could you share whether the application is a production or staging environment, and are there any specific compliance requirements (OWASP Top 10, PCI DSS, HIPAA, etc.) that the assessment should follow? Parminder
€2,200 EUR in 8 days
5.7
5.7

Hi, I’m interested in assisting with your web application penetration testing engagement. With extensive experience performing VAPT assessments for SaaS platforms, enterprise applications, and compliance-driven environments, I can help identify and validate security vulnerabilities across your application. Scope Coverage: • Authentication and authorization testing • Session management assessment • Data handling and storage security review • Input validation and business logic testing • OWASP Top 10 vulnerability assessment • Manual testing supported by industry-standard security tools Deliverables: • Detailed penetration testing report • Risk-rated vulnerability findings • Proof of concept/evidence for identified issues • Clear remediation recommendations • Executive summary for stakeholders I have hands-on experience conducting web application security assessments and can provide sample sanitized reports upon request. I would be happy to discuss the application architecture and testing scope in more detail. Best regards, SHD
€2,250 EUR in 7 days
5.3
5.3

As someone who has devoted the last 7+ years breaking into systems, web application and cloud security is my forte. My clients usually approach me after failed audits or near-miss incidents; I'm here to help you identify your security gaps promptly and efficiently. What sets me apart from the checkbox auditors is my knack for not just identifying vulnerabilities, but also providing clear-cut suggestions for remediation. With several certifications under my belt including CEH, OSCP, CISSP, PNPT, and eWPT, I have proven my mettle in the field time and time again. But it's not just about the certificates; it's about discovering real findings that could potentially save you from critical zero-day vulnerabilities. My list of skills includes Web & API penetration testing (not just OWASP Top 10), red teaming and adversary simulation, vulnerability assessments with Invicti, Nessus, Nmap, Qualys as well as secure code review to unearth logic flaws that most tend to overlook.
€2,500 EUR in 30 days
5.2
5.2

With over half a decade under my belt as a cybersecurity specialist, I've developed a comprehensive skill set perfectly tailored to your web app penetration test project. From the get-go, I bring an in-depth knowledge and practical expertise in areas such as authentication mechanisms, data handling and storage, and session management vulnerabilities. I've got real-world experience with the cybersecurity frameworks you'd expect: NIST, ISO 270001, and OWASP. In addition to that, I pack myself with a myriad of relevant certifications - OSCP, CEH, just to mention a few. My previous works majorly revolved around vulnerability assessments and penetration testing which makes my experience applicable to your needs. I have successfully identified security flaws from authentication mechanisms to data handling and storage while making sure to develop remediation strategies that align well with my client's individual needs. As a seasoned software engineer, I know the ins and outs of web applications which has no doubt amplified my precision in unraveling security risks.
€2,633.33 EUR in 5 days
4.7
4.7

Hey, I will test your web app's authentication mechanisms, data handling, and session management to surface real vulnerabilities, not just automated scanner output. Each finding will come with a severity rating and clear remediation steps your dev team can act on immediately. One thing that separates a useful pen test from a noisy one: manual testing of logic flaws around auth and session tokens. Scanners miss these almost every time, and they tend to be the highest-risk issues. I will focus there first, then layer in tooling for broader coverage. Questions: 1) Is the app currently in production, or do you have a staging environment I should test against? 2) Are there specific compliance requirements driving this test (PCI-DSS, SOC 2, or similar)? Looking forward to potentially working together. Thanks, Kamran
€1,707 EUR in 30 days
4.1
4.1

Hi there, We will perform a full penetration test of your web application covering authentication, session management, and data handling. Our approach starts with mapping the attack surface, then moves into manual testing. For authentication, we will test for credential stuffing, brute force, token predictability, and password reset flaws. For session management, we will verify cookie flags (Secure, HttpOnly, SameSite), session fixation, and timeout enforcement. We will also inspect how sensitive data is stored, transmitted, and exposed in API responses. The final report will include each vulnerability ranked by CVSS score, proof of concept steps, and clear remediation guidance your dev team will be able to act on immediately. Looking forward to your response. Best regards, Faizan
€1,656 EUR in 30 days
3.8
3.8

⭐⭐⭐⭐⭐ Expert Web Application Penetration Testing to Identify Vulnerabilities ❇️ Hi My Friend, I hope you are doing well. I've reviewed your project requirements and noticed you're looking for an experienced security professional for web application penetration testing. Look no further; Zohaib is here to help you! My team has successfully completed 50+ similar projects focused on identifying security vulnerabilities. I will conduct a thorough assessment, focusing on authentication, data handling, and session management to ensure your application's security. ➡️ Why Me? I can easily handle your web application penetration testing as I have 5 years of experience in security assessments, specializing in vulnerability identification. My expertise includes authentication protocols, data security, and session management vulnerabilities. Additionally, I have a strong grip on relevant technologies, which will ensure a detailed and effective approach to your project. ➡️ Let's have a quick chat to discuss your project in detail, and I can show you examples of my previous work. I look forward to discussing this with you! ➡️ Skills & Experience: ✅ Web Application Security ✅ Penetration Testing ✅ Vulnerability Assessment ✅ Authentication Protocols ✅ Data Handling Security ✅ Session Management ✅ Security Reporting ✅ Risk Analysis ✅ Network Security ✅ OWASP Guidelines ✅ Security Compliance ✅ Threat Modeling Waiting for your response! Best Regards, Zohaib
€1,800 EUR in 2 days
3.5
3.5

Hi! My name is Matías and I believe I am an exceptional fit for your comprehensive web application penetration test. With over a decade-long track record in web and mobile application development, I've built a deep understanding of security risks and how to mitigate them. In fact, I prioritized security measures from the inception of any project I work on as reflected in my use of proven authentication protocols, data security, and session management techniques. My skills align perfectly with your project scope; as a skilled full-stack developer proficient in backend & APIs with PHP (Laravel, Symfony, CodeIgniter), I have developed clean, scalable, and robust web applications which would give me an informed insight while conducting this test for your system especially through various targeted penetration tests. In terms of credentials, I hold relevant certifications like the OSCP and CEH which further affirm my ability to execute efficient penetration testing. Beyond just identifying vulnerabilities - my greatest commitment is ensuring that you are well-versed with the risks your application could face. Thus, you can count on receiving a detailed report from me with identified vulnerabilities as well as practical recommendations for remediation. Trust me to help secure your system beyond expectation – let's get started on this profoundly significant project together!
€2,250 EUR in 7 days
2.8
2.8

Hi there, I can run a thorough penetration test on your web app and deliver a report that actually helps you fix things. I work with standard security tools and methodologies daily—Nmap for reconnaissance, OWASP ZAP and Nikto for vulnerability scanning, and manual testing for logic flaws that automated scanners miss . Authentication, session management, and data handling are exactly where I focus. One engagement that comes to mind: a fintech platform with solid fundamentals but a subtle flaw in their password reset flow. An automated scanner missed it, but manual testing revealed the token wasn't invalidated after use, allowing repeated reset attempts. I documented the exploit, referenced the OWASP category, and gave them a clean fix. They patched it within two days . For your test, I'll follow a structured methodology: reconnaissance, scanning, exploitation, and reporting. You'll get a detailed breakdown with severity levels, proof-of-concept steps, and clear remediation paths mapped to OWASP Top 10 categories . I hold relevant certifications and have delivered similar reports that engineers can actually implement without extra hand-holding. Timeline: 7 days for the full assessment and report. Budget: €2,200 EUR. Let me know if you'd like to share the application URL so I can give you a more precise scope. Thanks!
€2,250 EUR in 7 days
2.2
2.2

With an exceptional track record in Full Stack Web Development and a deep understanding of Website Testing, I am uniquely positioned to meet your needs for a Comprehensive Web App Pen Test. As a seasoned freelance software engineer, I've honed my skills to ensure every project meets professional standards and exceeds client expectations. Having implemented notable websites and optimized online presence using WordPress Development and SEO techniques, I bring the expertise to tackle all facets of your test. Moreover, my certifications as an Offensive Security Certified Professional (OSCP) and Certified Ethical Hacker (CEH) speak to my commitment to this field. I possess a robust knowledge base in authentication protocols, data security, session management vulnerabilities, all integral parts of your desired scope. My approach has always been more about delivering solutions than mere project completion. Thus, if you entrust me with your comprehensive web app pen test, expect not just a detailed report pointing out vulnerabilities but recommendations for their remediation as well. Choose me today for timely delivery, clear communication, high quality results-oriented output and long-term collaboration that will lace your business with growth solutions.
€2,250 EUR in 7 days
0.0
0.0

I understand you need a comprehensive web application penetration test focused on identifying vulnerabilities in authentication mechanisms, data handling and storage, and session management. I recently completed a similar engagement for an e-commerce platform, uncovering critical authentication bypass flaws that were promptly remediated. My approach will involve a thorough manual and automated assessment using tools like Burp Suite Professional for proxying and vulnerability scanning, alongside OWASP ZAP for broader coverage. I will systematically test for common and complex vulnerabilities within the specified scope, culminating in a detailed report outlining each finding, its impact, and actionable remediation steps, complete with reproducible proof-of-concept examples. Given the focus on data handling and storage, what specific types of sensitive data, if any, are processed or stored by the application? Ready to start as soon as you confirm scope.
€2,750 EUR in 21 days
0.0
0.0

Rahul here, I can conduct a thorough web application penetration test to identify security vulnerabilities and provide clear remediation recommendations. * Authentication, session management, and data security testing * OWASP Top 10 aligned assessment * Detailed report with risk ratings and remediation steps * Retesting after fixes if needed I'm ready to start immediately and deliver a clear, actionable security assessment. Thank you for your consideration.
€1,900 EUR in 30 days
0.0
0.0

As a technology professional with a broad range of skills including web security and website testing, I would be an excellent choice for your comprehensive web app penetration test. With my deep understanding of the vulnerabilities that malicious actors exploit, particularly in areas such as authentication mechanisms, data handling, storage, and session management, I will leave no stone unturned in fortifying your application against cyber attacks. In addition to my experience, I hold several relevant certifications like OSCP, CEH that testify to my expertise in this domain. My refined skills in evaluating and detecting potential security vulnerabilities along with suggesting appropriate remediations will ensure you not only get a comprehensive report of existing shortcomings but also solid recommendations for improvements.
€2,250 EUR in 3 days
0.0
0.0

Jakarta Selatan, Indonesia
Payment method verified
Member since Jun 9, 2018
$300000-2500000 USD
$30-250 USD
€1500-3000 EUR
$1500-3000 USD
$15-25 USD / hour
₹1500-12500 INR
$15-25 USD / hour
₹1500-12500 INR
₹1250-2500 INR / hour
₹1500-12500 INR
$30-250 USD
$30-250 AUD
$30-250 USD
₹600-1500 INR
₹750-1250 INR / hour
$30-250 USD
₹12500-37500 INR
$750-1500 USD
₹750-1250 INR / hour
$250-750 USD
₹75000-150000 INR