
Closed
Posted
Paid on delivery
Looking for an experienced developer/security tester to analyze an OTP-based login system on a website that I am authorized to test. I need someone who can review the website’s OTP authentication workflow, identify security weaknesses, and suggest a secure way to streamline the authorized login process. Requirements: OTP login workflow analysis Website/API security testing Authentication flow review Security vulnerability assessment Clear report of findings Only authorized security testing. No unauthorized access or credential bypass.
Project ID: 40683077
23 proposals
Remote project
Active 10 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
23 freelancers are bidding on average ₹8,107 INR for this job

Hi, I can help assess your OTP-based authentication system through an authorized security review. I’ll analyze the complete OTP login workflow across the website and APIs, focusing on authentication logic, OTP generation/validation, rate limiting, session management, replay protection, enumeration risks, and common API/web security weaknesses. I’ll provide: • OTP workflow and authentication-flow analysis • Authorized web/API security testing • Vulnerability identification and risk assessment • Practical remediation recommendations • A clear, developer-friendly security report with evidence and severity All testing will remain strictly within the authorized scope, with no unauthorized access or credential bypass. I’m available to start immediately. Regards Kajal Majhi
₹13,000 INR in 7 days
5.6
5.6

Hello, I'm Rudra Kumar, an accomplished software QA engineer with a proven record of 7+ years in delivering top-notch products, and I am ideally suited to perform the security assessment of your website's OTP-based login system. My extensive experience spans the entirety of software testing and quality assurance - from manual to automation, functional to regression, and more – ensuring that I bring a holistic approach to identifying and addressing any security vulnerabilities you may have. Specifically, my expertise in API and database testing are major assets for this project. I've gained a deep understanding of REST API testing, including tools like Postman and Swagger, as well as authentication and authorization validation. Combining these skills with my familiarity with security practices such as OWASP Top 10, penetration testing, and vulnerability assessment, I can thoroughly analyze your system's security controls and provides actionable suggestions to bolster them according to industry best practices.
₹8,000 INR in 7 days
5.0
5.0

Hi, I can perform a focused security assessment of your OTP login system, covering OTP validation, API security, authentication flow, rate limiting, session security, and potential vulnerabilities. I’ll provide a clear report with severity, evidence, impact, and remediation recommendations. All testing will remain strictly within the authorized scope. Ready to start immediately.
₹7,000 INR in 4 days
2.6
2.6

I can review and security-test your SMS OTP authentication workflow within the authorized scope you provide. I will focus specifically on weaknesses that commonly affect OTP-based authentication, including OTP lifecycle and validation, rate limiting, replay/reuse issues, session handling, API authorization, account enumeration, workflow logic, and other authentication-related vulnerabilities. My approach combines manual testing with targeted security assessment rather than relying only on automated scanners. All testing will remain strictly within the agreed scope — no unauthorized access or credential bypass. Deliverables: • OTP authentication workflow analysis • Website/API security assessment • Validated findings with severity ratings • Evidence and reproduction steps where appropriate • Recommendations to strengthen and streamline the login flow • Clear final security report Before starting, I will confirm the target, authorized test accounts, API/login flow, scope, and testing limitations. I can start immediately. Please share the authorized scope and a brief overview of the current OTP workflow so I can begin the assessment.
₹8,000 INR in 2 days
1.5
1.5

Hi, I'm an ethical hacker/security tester with 5+ years in VAPT and bug bounty hunting, with a Hall of Fame recognition and achievement certificate from Max Healthcare for identifying critical vulnerabilities in production systems. OTP/authentication flow testing is one of my core specialties. My Approach for OTP Authentication Review: 1. NDA + scope confirmation, review of website/API endpoints involved in OTP flow 2. Map the complete login workflow (request OTP generation--> delivery verification--> session creation) 3. Test for common OTP weaknesses: - Rate limiting / brute-force resistance on OTP entry - OTP expiry & reuse validation - Predictability/weak randomness in OTP generation - Response manipulation (e.g., status code/response tampering to bypass verification) - Session fixation/token issues post-verification - API-level flaws (IDOR, missing auth checks on OTP endpoints) - Race conditions in verification logic 4. Document each finding with reproduction steps, risk rating, and evidence (screenshots/requests) 5. Provide a clear report with prioritized, practical remediation steps — plus recommendations to streamline the flow securely (e.g., adaptive rate-limiting, secure token handling) Timeline: 2–4 days depending on API complexity, with daily updates. All testing strictly within authorized scope — no destructive methods, no unauthorized access beyond what's agreed. Looking forward to discussing further under NDA.
₹11,000 INR in 7 days
0.2
0.2

Hello, On an SMS OTP login, the real risk rarely sits in the code itself but around it: code expiry, rate limiting on the verify endpoint, retry throttling and account enumeration. That's where most setups quietly leak. Before pinning anything down, three points would sharpen the work for you. Does the flow rely on a single SMS provider, or are fallback channels in play? Beyond a plain list of vulnerabilities, would a hardening blueprint for the OTP flow (safe expiry, throttling, anti-brute-force) be useful, or do you strictly need a findings report? And is written authorisation from the system owner already in place? For a job of this scope, expect the region of 180 to 337 EUR, firmed up once your answers are in. Looking forward to hearing from you. Kind regards, Eric
₹20,455 INR in 3 days
0.0
0.0

I'll review your OTP authentication workflow for security gaps: token generation and entropy, SMS delivery process, expiry and reuse protections, rate limiting on attempts, and API endpoint validation. I'll test for predictable tokens, replay attacks, brute force vulnerabilities, and common OTP implementation flaws. I've audited authentication systems and API security before. You'll get a ranked report with each finding, how to reproduce it, and concrete fixes. Two rounds of revision included. Share your website URL or staging environment access and I can start right away. Jeremy
₹5,700 INR in 3 days
0.0
0.0

Hello, I understand you need an authorized security assessment of an OTP-based login system, including the authentication workflow, website/API security, and identification of potential weaknesses. The goal is to strengthen the login process while keeping the authorized user experience secure and streamlined. Here’s what I can provide: End-to-end review of the OTP authentication flow, session handling, rate limits, and verification logic Authorized API and web security testing focused on authentication vulnerabilities and abuse cases Clear security report with findings, severity, evidence, remediation steps, and recommendations I bring over 4+ years of experience in web development, API testing, QA, and security-focused application analysis. I follow an authorization-first approach and can work within your defined testing scope without attempting unauthorized access or credential bypass. Just to clarify a few things: Do you have a staging environment available for the security assessment? What testing scope and authorization boundaries should I follow? Please come to the chat box to discuss more about your project. Best regards Indresh Kushwaha
₹8,000 INR in 7 days
0.0
0.0

Hi — OTP login hardening is exactly my area, and I'd give your authorized target a thorough, ethical review. What I check on an OTP auth flow: • Rate-limiting & lockout — brute-force / OTP-guessing resistance on both request and verify steps • OTP quality — length/entropy, reuse, replay, expiry, strict single-use enforcement • Flow logic — response/status manipulation, client-side trust, parallel-request 2FA bypass, forced-browsing past the OTP step • Enumeration & leakage — user/phone enumeration, verbose errors, OTP leaked in responses or logs • Post-login session/token handling — fixation, JWT/cookie flags • API auth on the underlying login endpoints Deliverable: a clear findings report — each issue with severity, reproduction steps and a concrete fix — plus a recommended streamlined-but-secure login design. Two things so I scope it right: is there a staging/test URL and a test number/account I can use, and roughly how many endpoints are in the login flow? Ricardo — 5.0★ here, security & testing background. I can start right away and deliver in ~3 days.
₹7,000 INR in 3 days
0.0
0.0

I am a full stack web dev with experience in QA testing and auth flows, I can test the otp login flow for you, point out possible bugs, suggest code modifications, and better security mechanisms. Please try to include the tech stack within your project description, helps a lot! Thanks
₹3,000 INR in 2 days
0.0
0.0

Your authorized OTP workflow needs a small test matrix that separates rate-limit gaps, session-state errors and unsafe recovery behavior. I would deliver a Three-Fixture OTP Security Assessment without attempting any credential bypass. Done when: 1. Valid OTP, expiry and one-time-use behavior is documented with evidence. 2. Repeated, replayed and stale OTP requests produce the expected rejection or throttling result. 3. Session state after success, failure and logout is reproduced and recorded without unauthorized access. Included: exact reproduction steps, expected and observed results, evidence, severity, suggested corrections and one retest. Fixed: INR 8,800 | Delivery: 3 days after authorized test access The three cases pass review or delivery is not finished. Same-case defects reported within seven days are corrected. To start, send the authorized test URL, test-account route and the allowed testing boundary. Quick question: should this cover web and mobile clients, or web only? Default if unspecified: web only.
₹8,800 INR in 3 days
0.0
0.0

I’ll assess the complete authentication flow, including OTP generation/validation, rate limiting, expiry, brute-force protection, session/token handling, API endpoints, input validation, error responses, and potential authentication bypasses. Recently, I have developed an tested similar APIs for a mobile application. I’ll document each finding with its severity, evidence, business impact, and recommended remediation. I’ll work strictly within the authorized scope and will not attempt unauthorized access or credential bypass. I’m available to start immediately and can provide a concise report with practical fixes at the end of the assessment.
₹8,500 INR in 7 days
0.0
0.0

"I am ready to perform a comprehensive, fully authorized security audit and assessment on your OTP-based login system. Using advanced Kali Linux environments (specifically Burp Suite for request interception and flow testing) combined with specialized technical analysis tools, I will thoroughly test your authentication pipeline. My review will focus on checking for rate-limiting flaws, potential brute-force vectors, session handling weaknesses, and OTP response leaks. Once the testing is complete, I will deliver a clear, structured vulnerability assessment report detailing my findings and actionable, secure ways to streamline the login process safely. Let's ensure your system is ironclad!"
₹10,000 INR in 4 days
0.0
0.0

Greetings. I can offer my expertise in this area, drawing upon 15 years of experience within the cybersecurity domain, encompassing mobile, API, IoT, and thick client environments. My background includes extensive penetration testing. I am available to assist with the security assessment of your SMS OTP logic and workflow. I can provide a comprehensive report within seven days, and my services will be rendered at a competitive rate of 5,000 rupees.
₹7,000 INR in 7 days
0.0
0.0

I can perform an authorized security assessment of your OTP login system, covering the complete web/API authentication workflow, OTP validation, expiration, retry/rate limiting, session handling, API security, and authentication logic. I will manually validate findings, provide clear evidence and severity ratings, and deliver practical remediation recommendations while keeping all testing strictly authorized and non-destructive.
₹7,000 INR in 4 days
0.0
0.0

Hi, I am Dinesh and I work as a penetration tester. I read your project details and I completely understand the requirements of it. I have good skills in web application testing, where I focus heavily on BAC vulnerability. I can test your application for OTP bypass vulnerability,find all endpoints related to it and test everything, while ensuring the application remains completely fine in production. You can provide me the details to discuss further.
₹6,000 INR in 4 days
0.0
0.0

Hi, I’m Hung. I specialize in web/API security testing with a strong focus on authentication logic and workflow flaws. For your OTP-based login system, I will specifically test: OTP Implementation & Logic: Rate limiting, brute-force resilience, OTP lifetime/reuse, response manipulation, and race conditions during generation/validation. API & Session Handling: Token issuance security, session fixation, privilege assignment post-authentication, and state tampering between the client and backend. Workflow Streamlining: Identifying friction points and suggesting secure architectural improvements (e.g., secure session persistence, token caching, or adaptive challenges) to make the login smoother without compromising security. You will receive a clear technical report with verified PoCs, CVSS severity ratings, actionable remediation steps, and one round of free re-testing after fixes are applied. I work strictly within authorized scopes. Ready to review the endpoint and start immediately.
₹8,500 INR in 4 days
0.0
0.0

Hi, I’m a Cyber Security professional with experience in web application security testing and vulnerability assessment. I can thoroughly review your OTP authentication workflow, APIs, session handling, and security controls. I’ll identify potential weaknesses such as OTP abuse, rate-limit issues, replay risks, and authentication flaws. All testing will be performed strictly within your authorized scope—no unauthorized access or credential bypass. You’ll receive a clear report with findings, risk levels, evidence, and practical remediation recommendations.
₹6,000 INR in 10 days
0.0
0.0

Here’s a professional proposal tailored to this OTP Login Security Testing project: > Hello, I’m interested in helping you assess the security of your OTP-based login system. I can review the complete OTP authentication workflow, website/API interactions, and authentication logic within the authorized testing scope. My assessment would focus on identifying weaknesses such as improper OTP validation, inadequate rate limiting, session/authentication issues, insecure API behavior, and other workflow-related security risks. I will provide a clear report containing: Security findings and severity Affected authentication/API components Evidence and reproduction details Risk assessment Practical recommendations for securing and streamlining the login flow I understand that this is an authorized security assessment, and I will strictly work within the agreed scope without attempting unauthorized access or credential bypass. I’m available to discuss the website/API environment and testing requirements and can begin once the scope and authorization are confirmed. Regards, Bharath Kumar
₹10,000 INR in 7 days
0.0
0.0

I specialize in authentication security testing and have built my own AI-driven security testing platform that specifically probes OTP workflows. Here's what I'll do for your OTP login: 1. Map the full OTP flow — request, delivery, verification, retry, expiry 2. Test for OTP enumeration (timing/response differences between valid/invalid codes) 3. Test for OTP brute-force feasibility (no rate limiting? predictable codes?) 4. Test for replay attacks (can an expired/used OTP be resubmitted?) 5. Test for race conditions in the verification endpoint 6. Test for OTP bypass via response manipulation 7. Check SMS delivery vs API — can OTP be intercepted or redirected? 8. Review the "streamline authorized login" ask — I'll suggest secure alternatives (TOTP fallback, magic links, device trust) without weakening security Deliverable: A concise report with each finding, severity, PoC, and a recommended fix. I can start immediately and deliver within 24 hours — this is a focused assessment I can turn around fast. NDA-ready. Authorized testing only, within scope.
₹4,000 INR in 1 day
0.0
0.0

Patna, India
Member since Aug 31, 2026
₹12500-37500 INR
₹1500-12500 INR
$15-25 USD / hour
$30-250 USD
₹12500-37500 INR
₹1500-12500 INR
₹12500-37500 INR
$250-750 USD
$10-30 USD
₹600-1500 INR
$15-25 USD / hour
£30-40 GBP
₹12500-37500 INR
₹1500-12500 INR
₹1500-12500 INR
₹75000-150000 INR
$10-30 USD
₹12500-37500 INR
₹750-1250 INR / hour
₹600-800 INR
$250-750 USD
$250-750 USD