
Closed
Posted
Paid on delivery
I need a thorough ethical hacker to focus exclusively on the login and authentication layer of my live website. Your task is to discover and document any weakness that could let an attacker slip past the sign-in screen—brute-force risks, credential-stuffing avenues, insecure password reset flows, session fixation, you name it. Use whatever industry-standard tooling you prefer (Burp Suite, OWASP ZAP, Kali, custom scripts), combine it with manual probing, and follow OWASP Top 10 practices. Payment pages and general UI aren’t in scope this round, but if things go well I may open that up afterward. Deliverables • Penetration-test report detailing each finding, its risk rating, and clear remediation steps • Proof-of-concept payloads or scripts where a vulnerability can be exploited • Brief retest after fixes to confirm the issues are closed Acceptance criteria: every critical or high-risk issue you uncover must be either fixed or have a documented compensating control, and the follow-up test must show the login path can no longer be breached by the same method. Let’s complete the first pass within one week, with quick daily check-ins so I can track progress.
Project ID: 40598176
12 proposals
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
12 freelancers are bidding on average ₹4,075 INR for this job

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
₹1,050 INR in 1 day
6.0
6.0

Hi, I can perform a focused penetration test of your website's authentication layer with an emphasis on identifying vulnerabilities that could lead to unauthorized access. Using a combination of manual testing and industry-standard tools such as Burp Suite Professional, OWASP ZAP, Kali Linux, and custom testing scripts, I'll assess brute-force protections, credential stuffing, password reset workflows, session management, session fixation, authentication bypasses, account enumeration, rate limiting, MFA (if applicable), and other OWASP Top 10 authentication-related risks. You'll receive a detailed professional report with risk ratings (CVSS), technical evidence, proof-of-concept where appropriate, and practical remediation recommendations. After your fixes are implemented, I'll conduct a verification retest to confirm the vulnerabilities have been successfully addressed. I can provide concise daily progress updates and complete the initial assessment within your one-week timeline. I have extensive experience in Web Application Penetration Testing, Digital Forensics, and Security Assessments, and I follow responsible disclosure and strict confidentiality throughout the engagement. Regards Kajal Majhi
₹15,000 INR in 7 days
5.3
5.3

As an IT specialist with a focus on Linux administration, I have developed a strong skill set in network security and penetration testing that aligns perfectly with your project requirements. Throughout my career, I have successfully identified and remediated complex technical issues, secured systems, and automated tasks using industry-standard tools like Burp Suite, OWASP ZAP, Kali, and custom scripts - all of which you've mentioned as your preferred tooling. With respect to your timeline expectations, my efficiency in identifying vulnerabilities and proposing actionable solutions will ensure that we complete the first pass within the given week while maintaining daily check-ins to update you on the progress made. In selecting my services, you are not only choosing someone with substantial experience in the field but a tenacious problem solver whose focus is on delivering reliable, secure, and scalable technical solutions for clients. I look forward to having the opportunity to leverage my skills and experience to improve your website's login security framework!
₹3,000 INR in 1 day
2.7
2.7

Hi! I can help thoroughly assess your website's login and authentication layer by performing a structured penetration test focused on identifying vulnerabilities before attackers can exploit them. I'll test for brute-force exposure, credential stuffing, insecure password reset workflows, session management flaws, authentication bypasses, session fixation, and other OWASP Top 10 authentication risks using industry-standard tools alongside manual testing. You'll receive a detailed penetration testing report with clear risk ratings, proof-of-concept evidence for verified findings, and practical remediation steps that your developers can implement quickly. After the fixes are applied, I'll perform a retest to confirm the vulnerabilities have been successfully resolved. I prioritize clear communication with regular progress updates throughout the engagement to keep the project on schedule. **Message me now to discuss your project, scope, and timeline, and let's secure your authentication system before vulnerabilities become real threats.**
₹5,000 INR in 2 days
0.0
0.0

Hi, I'd be happy to help test the security of your website's login and authentication system. I have nearly 8 years of experience in application security and penetration testing, including testing authentication, session management, access controls, and business logic vulnerabilities for enterprise applications. I'll perform a manual assessment supported by tools like Burp Suite and OWASP ZAP to check for: Brute-force and credential stuffing risks Authentication bypass Password reset and account recovery flaws Session fixation and session management issues User enumeration Rate limiting and account lockout weaknesses MFA bypass (if applicable) Other OWASP Top 10 authentication vulnerabilities I manually validate every finding to eliminate false positives and provide only confirmed issues. You'll receive a detailed report with severity ratings, proof of concept where applicable, and practical remediation recommendations. After the fixes are implemented, I'll perform a re-test to confirm the vulnerabilities have been resolved. Based on the scope, I can complete the initial assessment within 1–2 days and keep you updated throughout the engagement. Looking forward to working with you. Parthsarthi Biswal
₹4,000 INR in 2 days
0.0
0.0

Hi, I'd like to take this on. I'm a cybersecurity specialist with hands-on pentesting experience, recently completed a full security audit on a live web app covering login and auth flows specifically. I'll test for brute-force gaps, credential stuffing exposure, password reset flaws, session fixation, and auth bypass vectors, using Burp Suite, ZAP, SQLMap and manual testing mapped to OWASP Top 10. You'll get a report with risk ratings, PoC for exploitable issues, and clear remediation steps. After fixes, I'll retest to confirm the issues are closed. Can start right away, daily updates included.
₹3,000 INR in 2 days
0.0
0.0

Hello, Thank you for considering my proposal. I specialize in Web Application Penetration Testing and Bug Bounty, with a strong focus on identifying real, exploitable security vulnerabilities that could impact your business. For your project, I will perform a comprehensive security assessment combining both manual testing and industry-standard security tools to ensure maximum coverage. The assessment includes authentication, authorization, business logic, input validation, API security (if applicable), session management, and common OWASP Top 10 vulnerabilities, along with advanced attack vectors when relevant. You will receive: - A thorough penetration test tailored to your application. - A detailed professional report with risk ratings, technical findings, proof of concept, and clear remediation guidance. - Responsible disclosure and complete confidentiality throughout the engagement. - Clear communication and timely progress updates until the assessment is complete. My objective is not just to identify vulnerabilities, but to provide actionable recommendations that strengthen your application's security posture and help reduce real-world risk. I would be pleased to discuss your requirements in more detail and begin the assessment at your earliest convenience. Best regards.
₹1,050 INR in 7 days
0.0
0.0

Hello, I would be glad to help you perform a focused security assessment of your website's authentication and login functionality. I have a strong background in cybersecurity, web application security, Linux, and penetration testing. My assessment will follow OWASP Top 10 principles and combine automated security testing with careful manual verification to identify vulnerabilities affecting the authentication process. The assessment will include testing for: Brute-force and credential stuffing protections Authentication and authorization weaknesses Password reset and account recovery security Session management issues (session fixation, session handling, logout behavior) Input validation and common authentication-related vulnerabilities Security misconfigurations affecting the login process Upon completion, you will receive: A professional penetration testing report Risk ratings for each finding Proof-of-concept evidence where appropriate Clear remediation recommendations A follow-up verification after fixes to confirm the identified issues have been resolved I value clear communication and will provide regular progress updates throughout the engagement. Estimated delivery: 8 days I look forward to working with you. Best regards, Saad Moustahy
₹3,500 INR in 8 days
0.0
0.0

Hello, I read your project details carefully. You need an elite ethical hacker to secure the login and authentication layer of your live website, eliminating risks like brute-force, credential stuffing, password reset flaws, and session fixation using OWASP Top 10 guidelines. I am the perfect candidate for this job. Here is why: 1. Technical Expertise: I am Ranked #1 in Bangladesh on the TryHackMe National Leaderboard and within the Top 5% Globally among security practitioners. I also won 3rd place in the National Cyber Security Olympiad (University of Dhaka). 2. Advanced Auditing: I master Burp Suite, OWASP ZAP, and Kali Linux. I combine automated fuzzing with deep manual analysis to detect race conditions in password resets, session token entropy issues, and authentication bypasses. 3. Deliverables: I will provide a professional VAPT report containing risk scores, clear remediation steps, and working Proof-of-Concept (PoC) payloads/scripts. As per your criteria, I will maintain quick daily check-ins so you can track progress seamlessly. Once your developers patch the vulnerabilities, I will perform a brief complimentary retest to verify and confirm that the sign-in path is 100% hardened and can no longer be breached. I assure you of strict data confidentiality. Let's connect in chat to secure your authentication gateway immediately! Best regards, Jubed Mia Web Security Expert
₹1,050 INR in 7 days
0.0
0.0

Hello! I'm a Cybersecurity Specialist with expertise in Web, Mobile, and API Penetration Testing. I help businesses identify and remediate security vulnerabilities before they can be exploited. My expertise includes testing for OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), IDOR, Authentication & Authorization flaws, SSRF, Security Misconfigurations, and other application security issues. I use industry-standard tools such as Burp Suite, Nmap, MobSF, Nuclei, FFUF, OWASP ZAP, and more to perform thorough security assessments. My security research has been recognized by Apple, the U.S. Government, and several other organizations through responsible vulnerability disclosure and security acknowledgment programs. These recognitions reflect my commitment to ethical hacking and improving the security of real-world applications. When you work with me, you'll receive a detailed vulnerability report including proof of concept (PoC), risk assessment, and practical remediation recommendations. I focus on delivering accurate results, clear communication, and high-quality work on time. Let's secure your applications before attackers find the vulnerabilities.
₹1,200 INR in 3 days
0.0
0.0

With over a decade of experience focused on computer, network, and web security, I am extremely qualified to undertake your login security penetration test. My understanding of the risks you've mentioned—from brute force attacks to password resets to session fixation—is deep and up-to-date. I always follow industry standards such as OWASP Top 10 practices, which will be pivotal in assessing any vulnerabilities in your authentication system. My approach to this project would combine the use of powerful tools like Burp Suite, OWASP ZAP, Kali Linux alongside manual probing. I believe in thoroughness and precision when it comes to testing like this – working diligently with these tools will allow me to uncover weaknesses that automated processes often miss.
₹1,050 INR in 7 days
0.0
0.0

Nagpur, India
Member since Jul 22, 2026
₹600-1500 INR
$50-150 USD
$250-750 USD
$15-25 USD / hour
₹1500-12500 INR
₹1000-10000 INR / hour
₹600-1500 INR
₹1500-12500 INR
min $50 USD / hour
min ₹2500 INR / hour
$15-25 USD / hour
£250-750 GBP
$250-750 USD
$15-25 USD / hour
₹600-1500 INR
€18-36 EUR / hour
₹1500-12500 INR
$250-750 USD
₹1500-12500 INR
₹1500-12500 INR