
Closed
Posted
Paid on delivery
I need a thorough penetration test focused exclusively on phones, with coverage for both Android and iOS devices. The goal is to identify real-world attack paths, verify exploitability, and provide clear, actionable remediation guidance. I expect you to approach this as a black-box engagement that mirrors an external attacker’s perspective, diving into areas such as code weaknesses, insecure storage, improper platform usage, and over-permissive network calls. Please plan to use industry-standard tooling and methodology—think OWASP Mobile Top 10 checks with MobSF, dynamic analysis through Burp Suite or mitmproxy, runtime instrumentation via Frida, and network traffic inspection with Wireshark—while documenting every finding with proof of concept evidence and reproducible steps. Deliverables should include: • A concise executive summary for non-technical stakeholders • A detailed technical report (vulnerabilities, risk ratings, reproduction steps, and mitigation advice) • A debrief call or walkthrough to clarify findings and next steps Schedule is flexible, but I’d like an estimated timeline up front along with any device, build, or provisioning needs you have so we can get started quickly.
Project ID: 40504761
18 proposals
Remote project
Active 22 secs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
18 freelancers are bidding on average $37 USD for this job

Hello, I can perform a comprehensive mobile security assessment for both Android and iOS, focusing on OWASP Mobile Top 10 risks, insecure storage, authentication issues, API security, network traffic analysis, and runtime behavior. You’ll receive a clear executive summary, detailed technical report with risk ratings, reproduction steps, proof-of-concept evidence, and remediation recommendations. I can also walk through the findings and next steps after the assessment. Please share the build details, and I can outline the testing scope and timeline accordingly..
$30 USD in 7 days
5.5
5.5

I understand you're seeking a comprehensive mobile penetration test for Android and iOS, mirroring real-world attack vectors and focusing on actionable remediation, much like the detailed code and platform analysis described. My approach is designed to deliver precisely that level of depth and practical insight. My methodology will align with the OWASP Mobile Top 10, leveraging MobSF for static analysis to identify code weaknesses and insecure storage. For dynamic analysis, I'll utilize Burp Suite Pro to intercept and analyze network traffic, scrutinizing over-permissive network calls and improper platform usage. I will simulate black-box external attacker techniques, including fuzzing, reverse engineering where necessary, and exploiting identified vulnerabilities to demonstrate impact. How do you currently track and prioritize remediation efforts for identified vulnerabilities? Would you be available for a brief call next week to discuss specific device models and app versions you'd like to prioritize?
$73 USD in 21 days
4.3
4.3

Hi there, With 4 years of experience in Android development, backend systems, API security, and application analysis, I can assist with a structured security review of your mobile applications and help validate findings across Android and iOS builds. I’m familiar with OWASP Mobile Top 10 methodology, secure coding practices, traffic analysis, authentication flows, data storage reviews, and vulnerability documentation, providing clear reports with reproducible findings and remediation guidance. You’ll receive a detailed assessment report, risk prioritization, executive summary, and a walkthrough session to discuss findings and recommended fixes. Could you clarify whether source code access will be provided in addition to the Android/iOS builds, and whether the backend APIs are included within the testing scope?
$30 USD in 6 days
4.1
4.1

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive black-box mobile penetration test for both Android and iOS applications. Approach • Assessment aligned with OWASP Mobile Top 10 and MASVS • Static and dynamic analysis to identify insecure storage, authentication flaws, insecure API usage, weak cryptography, and platform misuse • Runtime testing using Frida, traffic interception via Burp Suite/mitmproxy, and network analysis with Wireshark • Validation of real-world attack paths with reproducible PoC evidence Toolset MobSF, Burp Suite, Frida, JADX, Ghidra, Wireshark, mitmproxy, and custom scripts Deliverables • Executive summary for stakeholders • Detailed technical report with CVSS severity ratings, PoCs, reproduction steps, and remediation guidance • Debrief session to review findings and answer questions Timeline Typically 5–10 business days, depending on application complexity and scope. Requirements • Android APK / iOS IPA (or TestFlight access) • Test accounts and user roles (if available) • Any specific testing constraints or scope requirements We have experience securing mobile, SaaS, fintech, healthcare, and enterprise applications and can start immediately once access is provided.
$200 USD in 7 days
3.6
3.6

With over 9 years in the industry - developing and testing software with an emphasis on security - I am confident that I can deliver above and beyond your expectations for this project. My experience extends to both Android and iOS devices, mirroring an 'external attacker's perspective' to hunt down every potential vulnerability. I perform a thorough task, examining areas such as insecure storage, code weaknesses, improper platform usage and over-permissive network calls. In terms of methodology and tooling, rest assured, I'm well acquainted with OWASP Mobile Top 10 checks with MobSF, dynamic analysis through Burp Suite or mitmproxy, runtime instrumentation via Frida, and network traffic inspection with Wireshark—a culmination of practices that adhere to industry standards. Additionally, I would furnish a comprehensive report complete with proof-of-concept evidence and reproducible steps that showcase my ability to clearly communicate complex issues. What distinguishes me is not just my technical expertise, but my dedication to meaningful bugs finding and improving overall product quality; something invaluable for a project rooted in security like this. Moreover, I have worked on similar projects in the past plus a strong background in AI-testing and finance/ERP systems—combining these proficiencies will make me your ideal candidate for executing not just the penetration test but provision device requirements too. So let's get started!
$10 USD in 7 days
1.1
1.1

Hey, I checked your requirement about performing a mobile-focused penetration test for both Android and iOS applications with a black-box security approach. You need a complete security assessment that simulates real-world attacker behavior to identify vulnerabilities in areas like insecure storage, weak authentication, API exposure, improper platform usage, and network-level weaknesses, followed by clear remediation guidance. I can handle this by conducting a structured mobile penetration testing process aligned with OWASP Mobile Top 10 standards. This will include static and dynamic analysis, traffic inspection, runtime testing, and manual exploitation validation to confirm real-world impact. Each issue will be documented with proof of concept, reproduction steps, risk severity, and actionable fixes. The final delivery will include an executive summary for stakeholders, a detailed technical vulnerability report, and a walkthrough session to explain findings and remediation steps clearly. Before we proceed, I have a quick question: Will you be providing signed production builds, or should I work with debug/test versions of both Android and iOS apps? Best Regards
$20 USD in 2 days
0.0
0.0

Hello, I can help you with a thorough penetration test for both Android and iOS devices. Approach: • Black-box engagement mirroring an external attacker's perspective • Covering code weaknesses, insecure storage, improper platform usage, and over-permissive network calls • Using industry-standard tools: OWASP Mobile Top 10, MobSF, Burp Suite, mitmproxy, Frida, and Wireshark Technologies: • Android and iOS platforms Extras: • Every finding documented with proof of concept evidence and reproducible steps • A concise executive summary for non-technical stakeholders • A detailed technical report with risk ratings, reproduction steps, and mitigation advice • A debrief call or walkthrough to clarify findings and next steps Timeline: • Flexible, but I can start within 1–2 days once I have the app build or APK/IPA files. No special device or provisioning needs on my end. Goal: To deliver a clear, actionable security assessment that identifies real-world attack paths and helps you fix them—hassle-free. Ready to get started. Agustin
$50 USD in 1 day
0.0
0.0

Hi, I can perform a black-box mobile penetration test for your Android and iOS apps. I have 6+ years in QA and security testing (OWASP) for fintech, insurance, and oil & gas domains. What I will cover (OWASP Mobile Top 10): - Insecure data storage - Hardcoded secrets - Weak network communication - Authentication & session flaws - Code tampering & reverse engineering Tools I will use: - MobSF for static analysis - Burp Suite / mitmproxy for traffic interception - Frida for runtime instrumentation - Wireshark for network inspection Deliverables: 1. Executive summary (non-technical, risk ratings) 2. Technical report (vulnerabilities, PoC screenshots, reproduction steps, remediation) 3. 30-min debrief call Timeline: 5-7 business days What I need: APK (Android) and/or IPA (iOS) files + test credentials. Ready to start immediately. Thanks
$20 USD in 7 days
0.0
0.0

Identifying real-world attack paths on mobile devices requires a robust approach to penetration testing that mirrors external threats. By leveraging OWASP's Mobile Top 10 alongside tools like MobSF and Burp Suite, I will conduct a black-box assessment on both Android and iOS platforms, focusing on code weaknesses, insecure storage, and over-permissive network calls. Deliverables will include a concise executive summary for stakeholders, a detailed technical report with risk assessments, and a debrief call to clarify findings. The initial deliverable will be ready in 10 days. Should I send over a brief outline of how I'd tackle this?
$17 USD in 7 days
0.0
0.0

Hi! Will you be providing Android APKs/iOS builds and test accounts, or should the assessment be performed entirely from public access? I understand you need a black-box mobile penetration test focused on real-world exploitability, not just automated scans. I can perform OWASP Mobile Top 10 testing, static and dynamic analysis, validate findings with proof-of-concepts, and deliver executive and technical reports with clear remediation guidance and a walkthrough session.
$20 USD in 7 days
0.0
0.0

With a strong foundation in both manual and automated software testing, I'm perfectly positioned to excel at your mobile penetration testing project. I specialize in thoroughly covering all aspects of software requirements just as you require for this task. Throughout my career, I've worked with complex test conditions using tools and techniques similar to what you've mentioned (e.g., OWASP, Burp Suite, mitmproxy, Frida, Wireshark) and have gained significant expertise in identifying vulnerabilities and providing actionable mitigation strategies based on my findings. Beyond just finding bugs or vulnerabilities, my approach specifically emphasizes thoughtful reporting with measurable reproducibility steps as well as clear-handling of risk assessment and recommendations for improvements. Your need for a comprehensive range of deliverables from executive summary to technical report aligns perfectly with my extensive experience with documentation tools like TestRail and Excel. While schedule flexibility is something I understand is important, I assure you that speed will not compromise the quality of my work. Throughout our engagement, clear communication will be my utmost priority from timely updates to effective debrief calls or walkthroughs as essential. Let us get started quickly and ensure the security robustness of your mobile applications by seeing it through an external attackers' perspective.
$20 USD in 2 days
0.0
0.0

We are team from Galactix Solutions, Hyderabad, with 2+ years of experience in penetration testing and security assessments. Our team has hands-on expertise in Android and iOS mobile application security testing, following industry-standard methodologies such as OWASP Mobile Top 10, MobSF, Burp Suite, Frida, mitmproxy, and network traffic analysis. We focus on identifying real-world attack paths, validating exploitability, and providing clear remediation guidance with detailed documentation and proof-of-concept evidence. We can deliver both executive and technical reports along with a walkthrough of findings. If you accept our proposal, please contact us and we will gladly share details of our previous projects and portfolio.
$31 USD in 5 days
0.0
0.0

We are team from Galactix Solutions, Hyderabad, with 2+ years of experience in penetration testing and security assessments. Our team has hands-on expertise in Android and iOS mobile application security testing, following industry-standard methodologies such as OWASP Mobile Top 10, MobSF, Burp Suite, Frida, mitmproxy, and network traffic analysis. We focus on identifying real-world attack paths, validating exploitability, and providing clear remediation guidance with detailed documentation and proof-of-concept evidence. We can deliver both executive and technical reports along with a walkthrough of findings. If you accept our proposal, please contact us and we will gladly share details of our previous projects and portfolio.
$20 USD in 7 days
0.0
0.0

Hi, I am interested in your mobile application testing project. I have experience performing application testing, identifying issues, documenting findings, and providing clear reports with reproduction steps and recommendations. I am detail-oriented, committed to quality, and able to follow testing procedures carefully. I can communicate findings clearly and provide organized documentation to support issue resolution and product improvement. I am available to discuss the project requirements and timeline further. Thank you for your consideration.
$30 USD in 21 days
0.0
0.0

Hi! I saw your project about mobile penetration testing for Android & iOS. I'm an offensive security specialist with a proprietary platform (Mythos v3.2) that detects vulnerabilities in 14 seconds. WHAT I DELIVER: ✅ Complete vulnerability report (PDF) ✅ Technical report with code fixes ✅ Live demonstration of findings ✅ 7-day post-delivery support ⏱️ Delivery: 3-5 business days I can start TODAY. Want a free 15-minute demo to see what I can find? Best regards, Jose Alcala Offensive Security Consultant Mythos Security Consulting
$20 USD in 5 days
0.0
0.0

Sanaa, Yemen
Member since Jun 10, 2026
$250-750 USD
$25-50 USD / hour
₹12500-37500 INR
₹100-400 INR / hour
$10 USD
₹12500-37500 INR
₹12500-37500 INR
$180-185 USD / hour
$750-1500 USD
$10-30 USD
$250-750 USD
$2-8 USD / hour
$30-250 USD
$10-30 USD
₹600-1500 INR
₹750-1250 INR / hour
$10-30 AUD
$14-100 NZD
₹12500-37500 INR
₹600-1500 INR