
Closed
Posted
Paid on delivery
Our production web application needs a comprehensive gray-box penetration test that evaluates its overall security posture. Source-code access and limited internal documentation will be provided, yet I still expect the perspective of an external attacker. The assessment must explicitly explore: • SQL injection vectors • Cross-site scripting (XSS) risks • Possibilities for man-in-the-middle attacks on data in transit Feel free to use your preferred toolkit—Burp Suite, OWASP ZAP, Kali Linux modules, custom scripts—so long as the methods are reproducible. Deliverables • A concise executive summary in plain English outlining high-level findings and business impact • A detailed technical report that maps each finding to OWASP Top 10/CWE, includes proof-of-concept payloads, reproduction steps, screenshots, and suggested remediations • A retest plan so I can verify fixes internally The engagement is complete when every critical or high-severity issue is either resolved or has a documented mitigation path that we both agree on.
Project ID: 40658080
88 proposals
Remote project
Active 10 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
88 freelancers are bidding on average $3,808 USD for this job

Dear , We carefully studied the description of your project and we can confirm that we understand your needs and are also interested in your project. Our team has the necessary resources to start your project as soon as possible and complete it in a very short time. We are 25 years in this business and our technical specialists have strong experience in Linux, Web Security, Computer Security, MySQL, Penetration Testing, Network Security, Risk Assessment, Security Auditing and other technologies relevant to your project. Please, review our profile https://www.freelancer.com/u/tangramua where you can find detailed information about our company, our portfolio, and the client's recent reviews. Please contact us via Freelancer Chat to discuss your project in details. Best regards, Sales department Tangram Canada Inc.
$4,120 USD in 5 days
8.1
8.1

I am a cybersecurity specialist with extensive experience in conducting gray-box penetration tests for web applications. My background in using tools such as Burp Suite, OWASP ZAP, and various Kali Linux modules ensures that I can effectively evaluate your application's security posture while providing the perspective of an external attacker. Having worked on similar projects focusing on SQL injection, cross-site scripting (XSS), and man-in-the-middle vulnerabilities, I possess a strong understanding of identifying and remediating these threats. Each assessment I conduct is thorough and aligns with OWASP Top 10 and CWE standards, ensuring comprehensive coverage. I utilize custom scripts where necessary to uncover more subtle vulnerabilities, always ensuring the process is transparent and reproducible. I'm interested in discussing how I can assist further in securing your application. Could you share more about your current retesting process to ensure any remediations can be verified effectively?
$3,000 USD in 30 days
7.9
7.9

Hello, I'm Md Shofiur, a Certified Ethical Hacker and CEO of Pentest Testing Corp. With 10+ years of cybersecurity experience and extensive web/API penetration testing experience, I can conduct a thorough gray-box security assessment of your production application. I’ll combine an external-attacker perspective with the provided source code and documentation. Testing will specifically cover SQL injection, XSS, authentication/authorization, access control, session management, business logic, API security, sensitive-data exposure, misconfigurations, and MITM risks involving TLS and data in transit. My methodology combines Burp Suite Pro, OWASP ZAP, Kali Linux, Nmap, custom scripts, and manual code-assisted analysis. Findings will be validated using reproducible techniques while keeping production impact to a minimum. Deliverables: • Plain-English executive summary with business impact. • Detailed technical report mapped to OWASP Top 10/CWE. • CVSS severity ratings, screenshots, evidence, PoCs, and reproduction steps. • Practical remediation recommendations. • Retest plan and verification criteria. I’ll prioritize Critical and High findings and document an agreed mitigation path where immediate remediation isn't possible. Estimated timeline: 5–10 business days, depending on application size and source-code scope. I’m ready to review the application architecture, source code, documentation, and testing constraints and begin.
$4,000 USD in 14 days
7.5
7.5

With my extensive experience in information security and penetration testing, I am well equipped to conduct a comprehensive gray-box assessment of your web application. My toolkit includes Burp Suite, OWASP ZAP, Kali Linux modules, and custom scripts that enable detailed evaluation utilizing enterprise-grade methods. Having delivered 680+ projects in a decade emphasizes not only my expertise but the trust clients place in my ability to protect their systems. My approach to penetration testing aligns exactly with your requirements. I will examine your application for SQL injection vulnerabilities, cross-site scripting risks, and potential man-in-the-middle attacks on data in transit. My comprehensive technical report will include not only identification of these issues but also their mapping to OWASP Top 10/CWE, proof-of-concept payloads, reproduction steps, and screenshots—ensuring complete transparency throughout the process. In addition to technical prowess, my focus on delivering business-focused results sets me apart. The detailed executive summary in plain English that I provide identifies high-level findings and their potential impact on your organization. Furthermore, by creating a retest plan, I assure you that I'll be there every step of the way to help you implement the necessary fixes and reassure yourself of the effectiveness of the solutions we put in place.
$4,000 USD in 7 days
6.6
6.6

Hi, I can perform a controlled gray-box assessment of your production application, combining source-code review with external attacker-style testing across SQL injection, XSS, TLS/data-in-transit weaknesses, authentication flows, and related OWASP risks. Using Burp Suite, OWASP ZAP, and targeted scripts, I’ll document reproducible evidence, business impact, CWE/OWASP mappings, remediation guidance, and a practical retest plan. A few questions: * What authentication mechanisms and user roles are available for testing? * Can you provide a staging environment or defined production testing window to minimize operational risk? * Which application components or APIs are considered most business-critical? Best regards, Muhammad Usman
$3,850 USD in 4 days
6.3
6.3

Hi there, I’ve performed web application VAPT covering authenticated/unauthenticated attack paths, API security, SQL injection, XSS, and security misconfigurations, with reproducible PoCs and remediation-focused reporting. For your production application, I can work independently from the provided source code and limited documentation while maintaining an external-attacker perspective rather than relying only on code review. I’ll specifically validate SQL injection vectors, XSS risks, and man-in-the-middle/data-in-transit weaknesses using Burp Suite, OWASP testing methodology, Kali tools, and custom scripts where required. Each confirmed issue will include severity, OWASP Top 10/CWE mapping, payload, reproduction steps, screenshots, business impact, and practical remediation guidance. The final deliverables will include the plain-English executive summary, detailed technical report, and a retest plan. I’ll also track critical/high findings through remediation or an agreed documented mitigation path so the engagement has a clear closure point. I can provide relevant VAPT/security testing experience and work with your preferred testing window and environment. regards, SHD
$4,000 USD in 7 days
5.3
5.3

Dear Client, I read "Gray-Box Web App Penetration Test" carefully and understand you need a high-quality eCommerce mobile application that delivers a seamless shopping experience and drives sales. My hands-on experience with Web Security, MySQL aligns directly with what you need. I've built eCommerce applications with product catalogs, category management, advanced search, shopping cart, secure payment gateways, order tracking, user authentication, push notifications, wishlist, coupons, reviews, and admin dashboards — all designed for scalability, performance, and an excellent user experience. A few quick questions to get us started: 1. Do you already have UI/UX designs, or should I design the application as well? 2. Which payment gateway(s) and shipping providers would you like to integrate? 3. Do you need a customer app only, or also an admin panel and delivery partner application? Thanks & Regards, Deepak
$3,250 USD in 30 days
5.3
5.3

Hi there, I am a lead engineer based in Canada with over 15 years of experience building bespoke web applications; and system infrastructure for widely public applications and larger organizations. I am happy to discuss this opportunity with you. Please take a look at my profile or open a chat with me so I could share more.
$4,000 USD in 7 days
5.1
5.1

Hi, I’m interested in conducting a gray-box security assessment of your production application with the focus on identifying exploitable vulnerabilities from both an external attacker perspective and through the limited source-code access you provide. My approach would combine manual testing with automated tooling, focusing on real attack paths rather than simply running scanners. Key areas I would assess: SQL injection across authentication, search, filters and API endpoints XSS including reflected, stored and DOM-based vectors HTTPS/TLS configuration and potential man-in-the-middle exposure Authentication, authorization and session security API security and input validation IDOR and privilege escalation risks Sensitive data exposure and insecure configurations Security controls identified through source-code review I can use Burp Suite, OWASP ZAP, Kali Linux and custom scripts where appropriate, while keeping testing controlled and reproducible. Deliverables would include: Executive summary with business impact Detailed technical report mapped to OWASP Top 10 and CWE Severity and risk classification Reproduction steps and evidence/screenshots Safe proof-of-concept payloads Clear remediation recommendations Retest plan for validating fixes I’m available to begin after the required testing scope and authorization are confirmed. Best regards, Arun
$3,000 USD in 28 days
4.4
4.4

A gray-box test is only valuable if the code access sharpens the attack rather than narrows the scope. I will start by mapping every input point and trust boundary from the source, then attack the live application using the same blind approach an external hacker would, so the analysis stays grounded in reality. SQL injection, XSS, and data-in-transit weaknesses will be tested through the actual execution paths that matter, with PoCs that reproduce against production-like conditions. The hidden problem in most source-visible tests is normalization drift, where the code validates one form of input while the proxy, router, or backend parses another, so I will specifically hunt for those mismatches. Every finding will be tied to the exact request and trigger, scored by business impact, and mapped to OWASP/CWE for remediation. I will also flag anything else that changes the risk picture, even if it falls outside the requested categories, because leaving it out would distort the report.
$3,000 USD in 7 days
4.4
4.4

Greetings! I can conduct a comprehensive gray-box penetration test on your production web application, combining source code access with an external attacker's perspective. I would explore SQL injection, XSS, and man in the middle attack vectors using tools such as Burp Suite or custom scripts, ensuring all methods are reproducible. My deliverables would include an executive summary of high level findings and business impact, a detailed technical report mapping each finding to OWASP Top 10 or CWE with proof of concept payloads, reproduction steps, screenshots, and recommended remediations, plus a retest plan for internal verification. I would consider the engagement complete once all critical and high severity issues are resolved or have agreed mitigation paths. Let me know your testing timeline and any specific application areas to prioritize. Thanks, Revival
$3,000 USD in 30 days
4.1
4.1

Hi, I can conduct a structured gray-box penetration test of your production application, combining external attacker-style testing with the provided source code and documentation. I’ll specifically assess SQL injection, XSS, TLS/data-in-transit weaknesses, authentication/authorization issues, input validation, session security, and other relevant OWASP Top 10 risks while keeping testing controlled to avoid disrupting production. You’ll receive an executive summary, detailed technical findings mapped to OWASP/CWE, reproducible evidence and remediation guidance, plus a clear retest plan for verifying fixes. I’ll also document severity, business impact, affected components, reproduction steps, and recommended remediation for each confirmed issue. Best Regards, Fizza
$4,000 USD in 7 days
4.3
4.3

You’ll receive a comprehensive gray-box penetration test focused on your production web app’s security posture, with an external-attacker perspective informed by the provided source access and limited internal documentation. Deliverables: 1) Executive summary (plain English): high-level findings, business impact, and prioritized risk. 2) Detailed technical report: each issue mapped to OWASP Top 10 and relevant CWEs, including proof-of-concept payloads, step-by-step reproduction, and annotated evidence (e.g., request/response flows, findings screenshots) plus concrete remediation guidance. 3) Retest plan: verification steps your internal team can follow to confirm fixes and re-validate risk reduction. Coverage explicitly includes: • SQL injection vectors (validation of exploitability and impact) • Cross-site scripting (XSS) risks across relevant contexts • Man-in-the-middle possibilities for data in transit (protocol, transport, and session/data protections) Engagement closure criteria: every critical/high issue is either resolved or has an agreed documented mitigation path.
$3,000 USD in 6 days
3.8
3.8

==== Hi - Truong here ==== "GRAY-BOX WEB APP PENETRATION TEST" — you need clear security findings your team can fix. I’ll assess the application from both attacker and code-aware views, focusing on SQL injection, XSS, data transport risks, and other OWASP-related issues. Each finding will include reproduction steps, impact, and practical remediation guidance. The important part is separating real risks from false positives. I’ll verify issues manually and provide a retest path so your team can confirm fixes after changes. Do you already have the application architecture and test environment details ready, or should the first step be reviewing the provided documentation and access scope? Looking forward to working with you.
$3,000 USD in 25 days
3.9
3.9

As a full-stack developer with more than 8 years of experience in mobile and backend service development, I have honed exceptional skills in database management which will be indispensable for your gray-box penetration test. My expertise in Java, Python, JavaScript and databases like MySQL, PostgreSQL and MongoDB make me perfectly suited for this task. Combining these proficiencies allows me to thoroughly explore SQL injection vectors and dynamically detect any vulnerabilities associated with Cross-site scripting (XSS). Moreover, my extensive use of tools like Burp Suite and Kali Linux modules give me an added advantage to provide you with an in-depth examination of your web application. I appreciate the significance of data security and comprehend the complexities that come with mitigating man-in-the-middle attacks on data in transit. I assure you of my dedication to rendering a holistic assessment by leveraging not only set methodologies but also custom scripts peculiar to your need.!
$3,000 USD in 14 days
3.6
3.6

Hi, Your production web app needs a gray-box assessment that still behaves like an external attack. I can work from the source code and limited internal docs to test the real attack surface, especially SQL injection, XSS, and data-in-transit risks. I’ve performed similar web application security reviews using Burp Suite, OWASP ZAP, Kali tools, and custom scripts when reproducibility matters. I focus on practical testing, clear evidence, and findings that map cleanly to OWASP Top 10 and CWE. My approach is to review the code and documentation first, then validate issues through controlled exploitation, capture proof-of-concept payloads and screenshots, and document concise remediation steps. I’ll also provide a retest plan so your team can verify fixes with confidence. If this sounds right, I’m ready to get started. Best regards, Gabriel
$3,000 USD in 30 days
3.0
3.0

Title: Gray Box Web Application Penetration Test Hello, I can perform a structured gray box security assessment of your production application with an external attacker perspective. I’ll thoroughly test SQL injection, XSS, authentication and authorization issues, data in transit, and other relevant OWASP risks using reproducible methods. You’ll receive an executive summary, detailed technical findings with evidence and remediation guidance, plus a practical retest plan. I’m ready to begin once the scope and access are confirmed. Best regards
$3,100 USD in 7 days
2.9
2.9

As a member of Web Crest's highly skilled team, specializing in AI, SaaS, web and mobile development, I'm well acquainted with Linux systems and equipped to conduct an extensive gray-box penetration test on your web application. I'm accustomed to working with limited documentation and sources, ensuring I adopt the perspective of an external attacker, thus simulating real-world scenarios. My in-depth understanding of SQL injections vectors, cross-site scripting (XSS) risks and man-in-the-middle attacks enables me to precisely evaluate your application from a security perspective. Throughout my career, I've successfully employed tools like Burp Suite, OWASP ZAP, Kali Linux modules as well as my own custom scripts to ensure comprehensive vulnerability testing. Moreover, my deliverables are known for their impact and actionable insights. Delivering concise executive summaries highlighting high-level findings along with detailed technical reports that map each finding to OWASP Top 10/CWE. These reports include proofs-of-concept payloads, screenshots, and suggest multiple remediation paths for possible loopholes. My quality driven retest plan would help you internally verify all fixes. Choose me if you're looking for a seasoned professional who prioritizes transparency in communication and guarantees scalable and maintainable solutions aimed at securing your application now much more than ever in today’s evolving digital landscape.
$3,000 USD in 7 days
3.0
3.0

Hi, Aashiq here from Cape Town, South Africa. This project instantly caught my eye, so I had to reach out. I see you are looking for a thorough gray-box penetration test for your web application, focusing on SQL injection, XSS risks, and man-in-the-middle attacks. This shows you’re serious about securing your application, which is great to see. I have extensive experience in conducting penetration tests that help businesses bolster their security posture. My background includes using tools like Burp Suite and OWASP ZAP to uncover vulnerabilities and providing actionable insights. I can share samples of my previous successful projects if you'd like. Based on what you mentioned, here is how we would approach the project: - Review source code and internal documentation. - Conduct testing for SQL injection and XSS vulnerabilities. - Simulate man-in-the-middle attacks to assess data in transit. - Provide a clear, actionable report with remediation strategies. You can expect clear communication and a seamless, user-focused solution optimized for performance. Best Regards, Aashiq
$4,500 USD in 7 days
3.1
3.1

Being a Senior Software Engineer with over 20 years of experience, I have had the privilege of designing and delivering complex systems for global companies like Cisco Systems and Qualcomm, which required thorough security assessments at each level. I have been involved in building real-time and performance-critical systems that carry a lot of data in transit, making me well-versed in preemptive measures against man-in-the-middle attacks. Having worked on Full-stack and Mobile Development even for companies like Cisco Systems, I understand the importance of retest plan to ensure the effectiveness of the fixed vulnerabilities; an aspect deemed crucial in your project’s completion. With me, you not only get a python expert but also a full stack developer who can fully grasp internal accessibilities for Project completion. I will provide you with a detailed technical report including proof-of-concept payloads, suggesting remediations and retest plan for verification ensuring that every critical or high-severity issue is resolved or has a documented mitigation path.
$3,000 USD in 2 days
2.5
2.5

Montreal, Canada
Member since Feb 17, 2025
₹37500-75000 INR
$1500-3000 AUD
$3000-5000 USD
$250-750 USD
$10-100000 USD
₹1500-12500 INR
₹150000-250000 INR
₹600-1500 INR
$30-250 USD
€250-750 EUR
₹12500-37500 INR
$15-25 USD / hour
€18-36 EUR / hour
$10-30 USD
$250-750 USD
$250-750 USD
₹1500-12500 INR
$25-50 USD / hour
$15-25 USD / hour
$250-750 USD