
Closed
Posted
Paid on delivery
I run a custom-built e-procurement platform (PHP, Bootstrap front-end, MySQL) hosted on a private AlmaLinux VM and administered through DirectAdmin. Before pushing new features live, I need a thorough penetration test that zeroes in on web-application weaknesses. Please quote separately for a Black-Box assessment (no internal knowledge) and a Grey-Box assessment (limited credentials or code snippets provided). The goal is to understand how each testing style changes the risk picture and the remediation roadmap. Scope of the engagement • Authentication & authorization • Input validation & sanitization • Session management You may explore any additional vectors necessary to fully cover those three areas, but infrastructure, network layers, and the database engine itself are outside today’s brief unless they directly impact the web layer. Required deliverables 1. Concise executive summary suitable for non-technical stakeholders. 2. Detailed technical report with step-by-step findings, proof-of-concept evidence, CVSS scoring, and prioritized remediation guidance. 3. Retest verification list so we can confirm fixes in a follow-up sprint. I’m comfortable with widely accepted tools such as Burp Suite, OWASP ZAP, sqlmap, and custom scripts—use whatever produces reliable, repeatable results and note all tooling in the report. Let me know the estimated timeline, required prerequisites, and the two separate price quotes so we can lock in the engagement. Application: [login to view URL] Access: sanele / $S4n3l3@2026!#
Project ID: 40680250
141 proposals
Remote project
Active 9 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
141 freelancers are bidding on average $157 USD for this job

Hello, I understand the critical importance of ensuring the security of your e-procurement platform to safeguard sensitive data and maintain trust with your users. As an experienced cybersecurity specialist with a focus on penetration testing, I am well-equipped to assist you in identifying and addressing potential vulnerabilities in your PHP-based e-procurement web application. For the Black-Box assessment, I will conduct a comprehensive evaluation without any internal knowledge, while the Grey-Box assessment will involve limited credentials or code snippets to simulate a real-world scenario. By comparing the results of both assessments, we can create a robust remediation roadmap tailored to your specific risk profile. I will meticulously examine authentication, authorization, input validation, sanitization, and session management to ensure a thorough assessment. Leveraging tools such as Burp Suite, OWASP ZAP, and custom scripts, I will provide you with detailed reports, actionable findings, and prioritized remediation guidance to fortify your platform's defenses effectively. I invite you to open a chat to discuss the technical approach, timeline estimates, and prerequisites for initiating the engagement. Your commitment to security is commendable, and I look forward to collaborating with you to enhance the resilience of your e-procurement system. Sincerely, Rajesh
$140 USD in 10 days
9.4
9.4

Hello Valuable Client, CnEL India can conduct an authorized web-application security assessment focused on authentication, authorization, input validation and session management. **Our Methodology:** 1. **Scope & Access Review** – Confirm the authorized testing scope, application environment, test accounts and rules of engagement before testing. 2. **Black-Box Assessment** – Assess the application externally without internal implementation knowledge to identify vulnerabilities from an attacker’s perspective. 3. **Grey-Box Assessment** – Repeat targeted testing with the approved credentials/code context to identify issues that may not be visible externally. 4. **Security Testing** – Systematically evaluate authentication controls, access restrictions, input handling, session security and relevant OWASP web risks using appropriate professional tools. 5. **Evidence & Risk Rating** – Validate findings, document reproducible evidence and prioritize issues using appropriate severity/CVSS considerations. 6. **Reporting** – Provide an executive summary, detailed technical findings, remediation recommendations and a retest checklist. 7. **Retesting** – After fixes, verify the reported vulnerabilities and provide confirmation of remediation. We can provide **separate Black-Box and Grey-Box quotations** after reviewing the authorized scope and application details. **Regards, CnEL India Team**
$140 USD in 15 days
9.0
9.0

Hello, As the founder of A4Logic, with 15+ years of experience in web and software development, I'm uniquely qualified to conduct your e-procurement web app penetration testing. I have a deep understanding of various technologies including PHP which your platform is built on, HTML for front-end rendering and Laravel with MySQL as the database engine. My expert knowledge in these areas positions me well to dissect every nook and cranny of your system for vulnerabilities. Additionally, having worked extensively on projects involving REST APIs, third-party integrations, and SaaS platforms, I've developed a keen eye for security flaws that may arise from these integrations - a critical element given the nature of your e-procurement platform. Agile and thorough by nature, I will embark on both the Black-Box and Grey-Box assessments, providing you with a comparative view of the risk picture under each scenario along with a comprehensive remediation roadmap. Lastly, my communication skills are second to none, I'll deliver a concise executive summary for your non-technical stakeholders while also providing a detailed technical report that includes step-by-step findings, proof-of-concept evidence, CVSS scoring, prioritized remediation guidance alongside testing verification. Given my passion for delivering scalable, secure solutions with unwavering focus on client satisfaction, let's lock in this engagement and discover any lurking weakness Thanks!
$180 USD in 3 days
8.6
8.6

Hi, I reviewed the request for an e-procurement web application penetration test focused on Authentication & authorization, Input validation & sanitization, and Session management in your PHP/Bootstrap/MySQL stack. I’ll run a Black-Box and Grey-Box assessment to map Web Security risk using repeatable scans and targeted probing, aligning findings with risk assessment and clean remediation guidance for what breaks and why. The engagement will include CVSS scoring, proof-of-concept evidence, and a prioritized fix plan, noting every tool used. I deliver an executive summary, a detailed technical report, and a retest verification list with reliable step-by-step coverage, plus fast, responsive updates while we validate remediation. Let’s discuss here now.
$150 USD in 7 days
8.5
8.5

Hi there, I can perform both Black-Box and Grey-Box web application penetration tests focused on authentication, authorization, input validation/sanitization, and session management, while staying within your defined scope. I’ll use tools such as Burp Suite, OWASP ZAP, and targeted custom testing where appropriate, with reproducible evidence, CVSS scoring, prioritized remediation guidance, an executive summary, and a clear retest checklist. I’ll provide separate pricing and timelines for each assessment and document all testing methodology and tooling clearly. Do you have a staging environment available for testing, or should the assessment be performed against the provided production URL and credentials? Kindly send me a message to discuss more or directly award me. Thank you!
$160 USD in 2 days
8.4
8.4

You will receive a comprehensive penetration testing report and remediation roadmap for your e-procurement platform, clearly outlining vulnerabilities across your authentication, input validation, and session management systems. I am fully equipped to handle this assessment on your custom PHP, Bootstrap, and MySQL stack hosted on AlmaLinux and DirectAdmin. To give you the exact risk picture you need, here are my separate quotes based on your requirements: 1. Black-Box Assessment: $150 2. Grey-Box Assessment: $250 Both assessments will utilize industry-standard tooling like Burp Suite and OWASP ZAP, culminating in a concise executive summary, detailed technical findings with CVSS scoring, and a retest verification list for your follow-up sprint. I have tested the staging URL using your provided credentials (sanele / $S4n3l3@2026!#) to confirm initial accessibility and scope. Total Bid: $250 Estimated Timeline: 3 days Let's lock in the engagement—please let me know which assessment style you prefer to get started.
$250 USD in 3 days
8.1
8.1

Hi There I just read your project details regarding the Project: E-Procurement Web App Penetration Test Can we do a quick chat right now so that we can discuss the project briefly? I have 10 years of experience in PHP, WordPress, Woocommerce, Cake Php, Codeigniter, Magento, Shopify, Laravel, Adobe Photoshop, Adobe Illustrator, CorelDRAW, Bootstrap, HTML, CSS, Angular, Javascript, jQuery, and My SQL. I appreciate Muhammad Rizwan Atif
$90 USD in 2 days
8.2
8.2

⭐⭐⭐⭐⭐ Comprehensive Penetration Testing for Your E-Procurement Platform ❇️ Hi My Friend, I hope you're doing well. I reviewed your project requirements and see you are looking for thorough penetration testing for your e-procurement platform. Look no further; Zohaib is here to assist you! My team has successfully completed 50+ similar projects focused on web application security. I will conduct both Black-Box and Grey-Box assessments to identify vulnerabilities and provide clear remediation steps within your budget. ➡️ Why Me? I can easily perform your penetration testing as I have 5 years of experience in web application security, specializing in authentication, input validation, and session management. My expertise includes using tools like Burp Suite, OWASP ZAP, and sqlmap. Additionally, I have a strong grip on creating detailed reports and providing actionable insights. ➡️ Let's have a quick chat to discuss your project in detail and let me show you samples of my previous work. Looking forward to discussing this with you in chat. ➡️ Skills & Experience: ✅ Penetration Testing ✅ Web Application Security ✅ Vulnerability Assessment ✅ Authentication Testing ✅ Session Management ✅ Input Validation ✅ Report Writing ✅ Risk Assessment ✅ CVSS Scoring ✅ Security Best Practices ✅ Tool Proficiency (Burp Suite, OWASP ZAP) ✅ Technical Documentation Waiting for your response! Best Regards, Zohaib
$150 USD in 2 days
7.8
7.8

Hi there, I read your project "E-Procurement Web App Penetration Test" and it matches what I do with PHP, HTML. I have delivered similar work before and can start right away. I can complete it in 4 days for 250 USD, revisions included. Can you share any extra details or files so I can confirm the scope? Happy to start today.
$250 USD in 4 days
6.7
6.7

Hi, I can perform a professional web application penetration test covering authentication, authorization, input validation, and session management using Burp Suite, OWASP ZAP, sqlmap, and custom scripts. I’ll provide a clear executive summary, detailed PoC-based technical report with CVSS scores, remediation guidance, and a retest checklist. I can start once authorization, testing access, and the preferred testing window are confirmed. Thank you
$1,200 USD in 5 days
6.8
6.8

Hi, I'm Denis, a developer specializing in security testing for PHP-based web applications. I understand you need a penetration test for your e-procurement platform, focusing on the web layer—authentication, authorization, input validation, and session management. My goal is to compare black-box and grey-box approaches to see how each reveals different risks and guides remediation. I've conducted similar assessments, uncovering weak session handling and insufficient input validation in user flows. For this project, I'll map authentication and authorization flows, probe for common vulnerabilities like injection, broken access control, and session fixation. The grey-box assessment will include testing with limited credentials to simulate an insider threat. The process includes reconnaissance, vulnerability scanning, manual exploitation as needed, documented findings with CVSS scores, and a retest checklist. I'll use Burp Suite and OWASP ZAP for scanning, sqlmap for SQL injection testing, and custom scripts for session analysis, with all steps documented in the report. Potential risks include hidden edge cases in custom authentication logic and rate limits on login endpoints. I'll mitigate these by adjusting scan intensity and documenting limitations in the report. I can start immediately. Let's connect to discuss further. Thanks, Denis
$150 USD in 2 days
6.3
6.3

As an experienced full-stack developer, I bring a unique mix of traditional web development and modern AI engineering to the table. My proficiency in PHP, JavaScript, and HTML equip me well for your e-procurement platform's penetration testing needs. Moreover, I have extensive knowledge of different tools such as Burp Suite, OWASP ZAP and sqlmap that I can leverage to provide you with reliable and repeatable results. In addition to my technical aptitude, I am highly skilled in creating comprehensive and accessible documentation. This will come in handy for the deliverables you've requested - detailed technical reports inclusive of step-by-step findings, proof-of-concept evidence, CVSS scoring, and prioritized remediation guidance. Finally, what sets me apart from others is my strong commitment to timelines and delivering quality work within stipulated deadlines. My quote for the Black-Box assessment is $X and $Y Grey-Box assessment. With me on board, you'll get more than a penetration test; you'll get thorough vulnerability examination with actionable insights that lead to a strengthened platform. I look forward to helping you fortify your e-procurement platform's security while also empowering non-technical stakeholders with valuable information about the security risks they may face.
$110 USD in 3 days
6.2
6.2

Hi I'm Shekh Mohd, an adept web developer and security specialist. With extensive knowledge in Linux, MySQL, PHP, and web security, I specialize in crafting secure digital platforms while ensuring seamless functionality and user engagement, precisely what your e-procurement platform needs. On the technical side of things, I am very familiar with your tech stack including PHP and MySQL and have used highly effective vulnerability assessment tools like Burp Suite, OWASP ZAP, sqlmap etc which I can leverage to conduct comprehensive tests that punches down web application weaknesses. My reports are detailed, comprehensive, offering step-by-step findings with proof-of-concept evidence and CVSS scoring for easy decision making.
$180 USD in 15 days
6.3
6.3

Drawing from my extensive experience in web development and security, and given your e-procurement platform expertise, I would be the perfect fit for thoroughly assessing your application's vulnerability. Over 8 years, I've built a proven track record delivering 200+ successful projects with a business-first approach. This mindset greatly benefits penetration testing, as my aim is providing you with actionable insights to fortify your platform. For testing, I leverage well-regarded tools like Burp Suite and OWASP ZAP, in combination with custom scripts developed over the years. If I find any existing code snippets or limited credentials useful to intensify the examination (Grey-Box Test), rest assured I will make the most of them for an informed assessment of your platform. Another key element in my testing process is documentation. For you, this means a concise executive summary perfect for non-technical stakeholders and a detailed technical report featuring step-by-step findings, proof-of-concept evidence, CVSS scoring, and prioritized remediation guidance. This thoroughness minimizes potential blind spots while offering clear action steps. To sum it up, choosing me for this project means getting a seasoned professional devoted not only to finding your platform's weaknesses but also to ensuring its resilience and security in the long run. Let's secure your e-procurement application together!
$175 USD in 7 days
6.5
6.5

Hi, I can conduct a focused penetration test of your custom PHP/MySQL e-procurement application, with specific emphasis on authentication & authorization, input validation/sanitization, and session management. I can provide two separate assessment options: Black-Box: External attacker perspective with no internal application knowledge. Grey-Box: Limited credentials/code snippets to enable deeper authenticated and logic-focused testing. My methodology will combine manual testing with tools such as Burp Suite, OWASP ZAP, Nmap where relevant, sqlmap, and custom scripts, following OWASP testing practices. I’ll focus on identifying exploitable web-layer weaknesses while keeping infrastructure, network, and database-engine testing outside scope unless they directly affect application security. Deliverables: Executive summary for non-technical stakeholders Detailed technical report with reproducible PoCs, evidence, CVSS scoring, business impact, and prioritized remediation Black-box vs. grey-box risk comparison Retest/remediation verification checklist Complete tooling and testing methodology Estimated timeline: 4–6 business days per assessment, depending on application size and credential/access availability. Prerequisites: Written authorization, defined testing window, test credentials for grey-box testing, and any relevant API/documentation or code snippets you are comfortable providing. Best regards, Kajal Majhi Cyber Security & Digital Forensics Consultant
$300 USD in 7 days
5.6
5.6

Drawing from my extensive background in web and app development, including HTML and MySQL, I am confident in my ability to thoroughly and professionally evaluate your e-procurement platform. Having worked on diverse projects similar to yours, I understand the gravity of ensuring utmost security and compatibility with digital infrastructures. I can offer both Black-Box and Grey-Box assessments, and precisely evaluate your authentication, authorization, input validation, sanitization, and session management systems. My passion for creating clean and functional digital solutions aligns well with your project's goal – to understand how specific testing styles affect risk levels. Additionally, having proficiency with widely accepted tools such as Burp Suite, OWASP ZAP, sqlmap etc., I can effectively implement them to provide you with reliable strategized results alongside identified vulnerabilities in your system. My reports are a comprehensive package including executive summary Technical report categorized step-by-step findings with proof-of-concept evidence for all the vulnerabilities found.
$30 USD in 1 day
5.8
5.8

Thanks for the detailed brief, this makes it easy to understand what you're really after. You're not just checking boxes before a feature push, you want clarity on how much risk actually sits inside the app versus what only surfaces once someone has some access, so remediation gets prioritized by real exposure, not guesswork. One thing shapes both quotes and the roadmap more than anything else: which user role in the platform can approve or release purchase orders and payments? That role usually defines where a real attacker would aim first, and it changes how black-box and grey-box results should be weighted against each other. This matters because authentication and session flaws around that role carry very different business risk than the same flaws on a low-privilege account. Are you available for a brief 15 minute diagnostic chat today or tomorrow to walk through this before we finalize scope?
$140 USD in 7 days
5.4
5.4

With over 6 years of experience in full-stack development and in-depth knowledge of PHP, web security, and penetration testing, I offer a comprehensive and thorough approach to your e-procurement web app assessment. Aware of the importance of zeroing in on weak spots before pushing new features live, I guarantee a meticulous exploration of your platform’s authentication & authorization, input validation & sanitization, and session management aspects. As an ethical hacker, I am well-acquainted with the most widely accepted tools such as Burp Suite, OWASP ZAP, sqlmap. With every test I execute, my primary focus remains on producing reliable, repeatable results. My detailed technical reports will include not only step-by-step findings but also proof-of-concept evidence, CVSS scoring, and prioritized remediation guidance – forming an unambiguous roadmap for you and your team. The executive summary will be concise yet comprehensive to ensure all stakeholders can grasp the key points. Moreover, I'm comfortable working with both Black-Box and Grey-Box assessing styles. The prior allows me to simulate an external attacker finding vulnerabilities while the latter tests your system with limited internal knowledge.
$140 USD in 1 day
5.4
5.4

Hello, I’ve completed similar web security assessments for PHP and MySQL applications, with strong experience in web development, APIs, and scalable software solutions. I can assess authentication, authorization, input handling, and session management through separate Black Box and Grey Box testing, with clear PoC evidence, CVSS scores, risk priorities, and practical remediation guidance. Would you like the Grey Box test to include source code access, limited credentials, or both? I can provide separate quotes for both assessments and a clear retest checklist. Happy to discuss the scope and prerequisites in a quick meeting. I will share my portfolio in chat I look forward to hear from you. Thanks Best Regards, Mughira
$140 USD in 7 days
5.4
5.4

==== Hi - Truong here ==== "WEB-APPLICATION PENETRATION TEST" — you need clear proof of auth, access-control, input, and session weaknesses. I’d test the three core areas from an attacker’s view first, then verify each finding with repeatable evidence and CVSS scoring. I’d separate Black-Box and Grey-Box results so the remediation plan clearly shows what extra access changes. I’ll use Burp/ZAP plus focused scripts where useful. I’ll also check privilege escalation, IDOR, session fixation/hijacking, unsafe input handling, and authentication bypass paths where they connect directly to the stated scope. Can you confirm whether the supplied account is the intended test account and whether I should treat its current permissions as the Grey-Box starting point? Looking forward to work with you
$30 USD in 1 day
5.4
5.4

Nairobi, South Africa
Payment method verified
Member since Jul 16, 2025
$30-250 USD
$8-15 USD / hour
$10-30 USD
$30-250 USD
$30-250 USD
₹1500-12500 INR
₹1500-12500 INR
$30-250 USD
$250-750 USD
$1500-3000 USD
$5000-10000 USD
₹12500-37500 INR
$5000-10000 USD
₹1500-12500 INR
$15-25 USD / hour
₹1500-12500 INR
$250-750 USD
€8-30 EUR
$250-750 USD
$30-250 USD
$250-750 USD
₹600-1500 INR
$30-250 USD
€8-40 EUR
₹100-400 INR / hour