
Completed
Posted
Paid on delivery
I need a full black-box penetration test of my production site, https://hvhesp.sergioeh.dev. The goal is to measure how well the current security defenses stand up against real-world attacks while staying aligned with the OWASP Top 10 risks. Environment details • Front end: React + Vite • Reverse proxy: Nginx • Live data: Production database has been fully backed up, so you are free to test against the active environment. Scope and priorities Authentication and authorization flows, all data input/output validation, and session management must receive special attention. I will supply a valid username-and-password account so you can assess both unauthenticated and authenticated areas of the app. Required deliverables • Comprehensive report outlining each finding, its risk rating, proof of concept, and clear remediation guidance • Executive summary that a non-technical stakeholder can understand • Methodology mapped to the OWASP Top 10 and any additional frameworks or tools you employed (e.g., Burp Suite, OWASP ZAP, Nmap) • Retest notes or confirmation steps so I can verify fixes later Acceptance criteria • No disruption of normal service for other users • All high- or critical-risk issues include reproducible steps and screenshots • Report delivered in PDF and editable format within the agreed timeline Provide your estimated timeline and the main tools you plan to use, and we can get started right away.
Project ID: 40626404
64 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

Hello, A production security test should provide more than automated scanner results — it should reveal how an attacker could actually interact with your application and where defenses need improvement. I can conduct a complete OWASP-aligned black-box penetration test for your React/Vite application, reviewing login flows, permissions, sessions, user inputs, API communication, database exposure risks, and server configuration through Nginx. My process combines automated discovery with manual verification to reduce false positives and identify meaningful security issues. You will receive a detailed PDF and editable report containing findings, risk levels, evidence, exploitation steps, mitigation guidance, and retest recommendations. I will treat your live environment carefully, using controlled testing methods to maintain availability while providing a realistic security assessment. I believe you are planning to strengthen your application before vulnerabilities become operational risks. I would be glad to help secure your platform. Looking forward to work with you. Thanks
€120 EUR in 3 days
3.4
3.4
64 freelancers are bidding on average €150 EUR for this job

Hi there, I see you need a full black-box OWASP Top 10 test on your React+Vite site behind Nginx, with authenticated access. I can run that against your production environment safely using your backup. What I'll do: ✅ Map the app with Burp Suite and OWASP ZAP, test auth flows and session handling with your provided test account ✅ Run input validation and SQL injection checks against your SQLite backend, plus CSRF, XSS, and IDOR risks ✅ Do a staged rollout of tests to avoid any impact, with a full backup verified before I start Skills: ✅ Web Security & OWASP Top 10 methodology ✅ Penetration Testing with Burp Suite, ZAP, Nmap ✅ Linux + Nginx and React.js/Vite understanding ✅ Network Security and session management analysis ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ 300+ projects delivered, 280+ five-star reviews Why me: I'm available 24/7 and respond fast, so you'll get updates as I work. Before I start, do you have any WAF rules or IP restrictions on that site I should know about? I can deliver the full report with retest notes in a PDF and editable format within 3 days for €131, and I'm ready to begin right now.
€131 EUR in 3 days
6.7
6.7

Hi, I reviewed your request for a full black-box penetration test of the production site, aligned to the OWASP Top 10, with special focus on authentication, authorization, validation, and session management. I’ll run a controlled assessment through your Nginx-reversed React + Vite application using realistic black-box flows, capturing evidence for React.js routes, session handling, and Web Security issues, including network security checks and SQL-related injection attempts where inputs touch the database. I’ll prioritize safety to avoid disruption for other users, provide clear proof with reproducible steps and remediation guidance, and deliver an executive summary plus a methodology mapping. Let’s discuss here now.
€250 EUR in 30 days
5.5
5.5

Full black-box coverage against the live environment, with authenticated and unauthenticated paths tested using the account you provide, is the right approach given the backup is already in place. - Recon and mapping: Nmap for network/service enumeration, then Burp Suite and OWASP ZAP for application-layer testing, covering the Nginx reverse proxy configuration (headers, TLS, misconfigurations) and the React/Vite front end's attack surface. - Authentication, authorization and session management: broken access control checks, session/token handling, IDOR testing, plus systematic input validation across all forms and API calls, mapped directly to OWASP Top 10 categories. - Open question: are the API endpoints documented (REST spec, Swagger, etc.) or should they be discovered through crawling and traffic analysis? This affects how much time goes into enumeration versus deep testing of known routes. Delivery fits the 7-day window you specified, ending with the full report (findings, risk ratings, PoC, remediation, executive summary, methodology, retest notes) in PDF and editable format. Treat the bid amount as an initial, orientative reference for the scope as described, not a final price — we'll confirm the exact figure once the API documentation question above is settled. Happy to do a quick 15-minute call here on Freelancer to align on scope, and you're welcome to check my profile and portfolio for related security work.
€250 EUR in 7 days
5.3
5.3

Hello, I have 9+ years of experience in Web Application Penetration Testing and Digital Forensics, and I can perform a thorough black-box security assessment of your production application with minimal impact to live users. My testing will focus on authentication, authorization, session management, input validation, business logic, and the OWASP Top 10, using tools such as Burp Suite Professional, OWASP ZAP, Nmap, Nikto, and manual verification to eliminate false positives. I will respect your stated rate limits and testing constraints to avoid service disruption. Deliverables: * Executive summary * Detailed technical report with CVSS-based risk ratings * Proof of Concept with screenshots * Remediation recommendations * OWASP Top 10 mapping * Retest guidance and verification steps * PDF and editable report Estimated timeline: 5–7 days after receiving written authorization and test credentials. Before starting, I would just need written authorization for production testing and confirmation of any restricted endpoints or testing windows. Regards Kajal Majhi
€250 EUR in 7 days
5.3
5.3

As an AI-focused agency proficient in various web technologies including web security, choosing us for your OWASP Web App Penetration Test is a decision you won't regret. Our expertise in React.js and SQLite align perfectly with your site's front end and live data environment respectively. Being well-versed with OWASP Top 10 risks, we ensure a comprehensive test that addresses everything from authentication flows to session management without disrupting normal service - a key priority for your project. Apart from offering you a detailed assessment of your system's security posture, what sets us apart is our commitment to long-term business value in all our projects. At the conclusion of the test, we'llprovide retest notes or confirmation steps so you can verify fixes later. Trust us with your projects – as we build intelligent automation workflows and scalable SaaS platforms for enterprises using the core skills that resonate fully with this task; your setup will be 100% secured against real-world attacks.
€75 EUR in 1 day
5.1
5.1

Hi, I'm a Cyber Security Researcher with practical experience gained through playing CTFs (Capture The Flag), engaging in Bug Bounties, and working as a Pentester. Notice: Don’t ask me to hack something u don’t OWN What I can do for you: Web/API/Android (OWASP TOP 10) Pentesting: You can also get this service from here: https://www.freelancer.com/service/web_security/web-app-penetration-test-owasp-top Lets Chat…
€140 EUR in 7 days
4.8
4.8

Hi, I understand your priority is to perform a comprehensive black-box penetration test on your production application while ensuring normal service remains unaffected. I have experience with web application security testing, OWASP Top 10 assessments, authentication and session testing, API security validation, and vulnerability reporting. I can thoroughly evaluate both authenticated and unauthenticated areas of your application and deliver a detailed report with risk ratings, proof of concept, remediation guidance, and retest steps. Could you please confirm if the application exposes any REST or GraphQL APIs that should be included in the assessment, or should the testing focus entirely on the web interface? Looking forward for positive response in the chatbox. Best Regards, Hassan H
€160 EUR in 7 days
4.2
4.2

Hi, how are you doing? I have considerable experience in security testing for web apps and I’ve worked on tests with OWASP Top 10 focus, including authenticated and unauthenticated flows, data validation, and session management. I can perform a full black-box assessment of your React/Vite front end behind Nginx, using Burp Suite and OWASP ZAP, with a detailed report, executive summary, and retest steps, plus reproducible steps and screenshots. Timeline and tools can be aligned to your needs; let me know further information, if interested.
€250 EUR in 5 days
3.9
3.9

Hi, I hope you're doing well. I understand you're looking for a comprehensive black-box penetration test of your production React/Vite application to identify security weaknesses against real-world attack scenarios while aligning the assessment with OWASP Top 10 standards. The main goal is to validate authentication, authorization, input handling, session security, and overall application resilience without impacting normal users. I will perform a structured security assessment covering application workflows, API interactions, authentication controls, access management, input/output validation, and common web vulnerabilities using industry-standard testing approaches and tools such as Burp Suite, OWASP ZAP, and supporting security utilities where appropriate. I will provide a detailed report with risk ratings, evidence, reproduction steps, remediation guidance, and retest recommendations in a clear format for both technical and non-technical stakeholders. My focus is on delivering a thorough, responsible security assessment with actionable findings, clear documentation, and practical recommendations to strengthen your application's security posture. Best regards, Heorhii
€100 EUR in 5 days
3.6
3.6

With your project's focus on meticulously assessing the security vulnerabilities of your production site, my extensive experience in secure web application development and penetration testing will make me a perfect fit for the job. I have an in-depth understanding of the OWASP Top 10 risks, ensuring that my methodology will adequately address each aspect during the test and provide you with actionable insights for remediation. In my work as a full-stack developer with strong proficiency in PHP, Node.js, Vue.js, and C#, I have consistently prioritized developing efficient and scalable applications with robust defenses against potential attacks. I have sharpened my skills through hands-on experience using several security frameworks and tools, including OWASP ZAP and Nmap, which I plan to employ for this project. Furthermore, I am dedicated to delivering comprehensive deliverables tailored to both technical and non-technical stakeholders. You can expect an executive summary that clearly communicates key findings while also providing you with a detailed report containing reproducible steps, risk rating, POCs and precise steps for mitigation. Rest assured my approach will neither disrupt your users' experiences nor compromise any data. My proven track record of meeting strict timelines will also be to your advantage as I aim to provide you with detailed reports within the agreed timeline.
€140 EUR in 2 days
3.4
3.4

Hi, your site needs a full black-box test focused on the exact areas that usually break first: auth, authorization, input handling, and session control. I’ve done production-safe web application assessments before, including OWASP Top 10 coverage with Burp Suite, OWASP ZAP, Nmap, and careful manual testing. I’ll validate both unauthenticated and authenticated paths, look for privilege escalation, injection, session flaws, and any exposure in the React/Vite and Nginx layers. My approach is controlled and non-disruptive: map the attack surface, test each flow methodically, document every finding with proof, then provide clear remediation steps and retest guidance. You’ll get an executive summary, technical detail, and a report that is easy to act on. If you’d like, I can start with the production-safe methodology and timeline immediately. Best regards, Gabriel
€250 EUR in 5 days
2.7
2.7

Hi! I can perform a thorough black-box penetration test of your production application while ensuring the assessment is non-disruptive and aligned with the OWASP Top 10 and OWASP WSTG. I'll test both unauthenticated and authenticated areas using the account you provide, with special attention to authentication, authorization, session management, input validation, business logic, and common web vulnerabilities such as SQL injection, XSS, CSRF, IDOR, and security misconfigurations. Before starting, I'll need your written authorization to test the production environment and the test account credentials. I look forward to helping you assess and strengthen your application's security.
€150 EUR in 2 days
2.0
2.0

Rough ballpark on the bid amount and timeline shown - real figures depend on the actual surface area once we dig in, so treat them as starting points. Your site is a React/Vite app sitting behind Nginx, and you want to know exactly how it holds up against the OWASP Top 10 in a real environment. That means black-box testing from the outside, then authenticated testing with the credentials you provide, with the heaviest focus on auth flows, session handling, and anything that touches user input or output. The end goal is a clear picture of what's exploitable today and a roadmap to fix it. Here's how we'd approach this: - Recon and surface mapping: passive recon first, then active scanning with Nmap and Nikto to map endpoints, headers, and exposed services without touching the app hard. - Unauthenticated testing: run OWASP ZAP and Burp Suite against public-facing routes, checking for injection points, misconfigurations, exposed error messages, and insecure Nginx headers. - Authenticated testing: use the credentials you supply to walk through auth and session flows, testing for broken access control, IDOR, privilege escalation, and improper token handling. - Input/output validation: manual and automated checks on every form, API call, and file upload path for XSS, SQLi, SSTI, and similar injection risks. - Report and retest pack: full PDF report with CVSS-rated findings, screenshots, reproducible PoC steps, an exec summary for non-technical readers, and a retest checklist so you can confirm each fix independently. After a short scope chat we'll put together a written proposal covering deliverables, timeline, and a firm price. Would a 15 minute call this week work to go over the scope before we commit to numbers? Best, 96 Studio
€188 EUR in 7 days
1.1
1.1

⭐⭐⭐⭐⭐ I can perform a thorough black-box penetration test of your production app aligned with OWASP Top 10, focusing on authentication flows, session management, input validation, and privilege boundaries without disrupting live users. I’ll use a combination of Burp Suite, OWASP ZAP, and targeted manual testing to uncover real-world vulnerabilities, then deliver a clear, professional report with risk ratings, reproducible PoCs, annotated evidence, and precise remediation guidance, along with an executive summary and verification steps—ensuring you have actionable, audit-ready results within a fast turnaround.
€120 EUR in 1 day
0.8
0.8

Hello, I read your requirements carefully. I understand you need a professional black-box penetration test that reflects real-world attack scenarios while keeping the production service stable. I will respect the agreed scope and avoid any disruptive testing that could affect other users. My assessment will focus on authentication, authorization, session management and input validation, following the OWASP Top 10 methodology. I will also review security headers, API behavior, access controls and common web vulnerabilities using industry-standard tools such as Burp Suite, OWASP ZAP and Nmap where appropriate. The final report will be clear and practical. It will include an executive summary, detailed findings with risk ratings, proof of concept, screenshots, remediation recommendations and verification steps so you can confidently retest each fix after implementation. Before starting, I would review the application structure and use the test account you provide to evaluate both authenticated and unauthenticated areas without interrupting normal operation. One important question: are there any specific endpoints, API routes or features that you consider business-critical and would like me to prioritize during the assessment? Best regards.
€140 EUR in 7 days
0.9
0.9

⚠️ If you're not happy, you don’t pay. ⚠️ Hi Sergio, thank you for checking my proposal and sharing the detailed project brief. I can perform a full black-box penetration test on your site using tools like Burp Suite and OWASP ZAP with a comprehensive, risk-aware approach. I will deliver: • Detailed report of findings with risk ratings and remediation guidance • Executive summary for non-technical stakeholders • Methodology aligned with OWASP Top 10 and any additional frameworks • Retesting notes to confirm fixes You will also receive: • Continuous communication throughout the testing process • Post-assessment support for remediation clarity I am confident I can execute your vision professionally and efficiently. Looking forward to discussing the timeline and next steps. Best regards, Chirag
€150 EUR in 7 days
0.0
0.0

Hi, I handle security assessments alongside ML and backend systems, including auth flows, API surfaces, and production-grade web stacks. The real challenge here is testing deeply without degrading live service. Session handling, token lifecycles, and privilege boundaries often hide subtle flaws. Input validation across client and proxy layers can also diverge, especially under authenticated states. Another risk area is ensuring findings are reproducible without relying on unstable conditions. How is traffic isolation handled during testing to avoid impacting real users? Are there rate limits or WAF rules that could skew results? Do you have logging or audit trails accessible for correlating test activity? I can align with your timeline once scope details are clarified.
€145 EUR in 7 days
0.0
0.0

Dear Client, I reviewed your project requirements and I am interested in working with you. I have extensive experience delivering Linux, SQLite, Network Security, Penetration Testing, React.js, Web Security, Vite, Nginx, Internet Security and Security Auditing. I focus on understanding the requirements clearly, providing a practical solution, and delivering accurate, well-documented work on schedule. I can review your existing materials, identify the best technical approach, and manage the project from planning through final delivery. You will receive clear communication, regular progress updates, and full support throughout the project. I am available to begin immediately and would be glad to discuss the scope, timeline, and budget. Best regards, Elijah M.
€200 EUR in 3 days
0.0
0.0

Hi, I've reviewed your project details for the OWASP Web App Penetration Test and am ready to conduct a thorough black-box audit of your React and Vite-based environment. I will focus on your Nginx configuration and authentication flows to identify vulnerabilities such as broken access control or injection risks. Using tools like Burp Suite Professional and OWASP ZAP, I will validate your defenses without disrupting your production service. You will receive a detailed PDF report including an executive summary, proof-of-concept screenshots for all findings, and clear remediation steps mapped to the OWASP Top 10. I can complete this assessment and deliver the final documentation within four days. Best regards, Khadija Tul Kubra
€50 EUR in 1 day
0.0
0.0

Get a production-ready, black-box OWASP Web App Penetration Test that stays aligned with the OWASP Top 10, without derailing normal service. You’ll receive: (1) an executive summary written for non-technical stakeholders, (2) a comprehensive finding report with risk ratings, proof-of-concept, and concrete remediation guidance, (3) methodology mapped to OWASP Top 10 plus the exact tools used (e.g., Burp Suite/OWASP ZAP, Nmap where applicable), and (4) retest/verification notes so fixes can be confirmed cleanly. Special focus areas include authentication & authorization flows, session management, and input/output validation across unauthenticated and authenticated paths using the supplied username/password. Deliverables will be provided in PDF and an editable format within the agreed timeline. Screenshots and reproducible steps are included for every High/Critical item to ensure actionable fixes.
€100 EUR in 2 days
0.0
0.0

Sevilla, Spain
Payment method verified
Member since Aug 4, 2026
€250-750 EUR
₹250000-500000 INR
₹1500-12500 INR
₹12500-37500 INR
$30-250 USD
$5000-10000 USD
$15-25 USD / hour
$250-750 USD
₹1500-12500 INR
₹600-1500 INR
$30-250 USD
₹750-1250 INR / hour
₹37500-75000 INR