
Closed
Posted
Paid on delivery
I need a seasoned ethical hacker to probe my public-facing web applications and surface every weakness before attackers do. The core goal is to identify vulnerabilities; no remediation work is required at this stage, but I do want clear, reproducible evidence for each flaw. Scope The assessment must cover the full web stack—front-end, back-end, APIs and any server-side components tied to the apps. Automated scanning is fine as a first pass, yet I expect you to validate every finding manually and look beyond scanner results for business-logic or access-control issues. High-priority findings Please focus your efforts on: • SQL injection • Cross-site scripting (XSS) • Cross-site request forgery (CSRF) You are free to uncover and report additional issue types, but the three above are non-negotiable. Methodology & tools Follow OWASP Testing Guide principles. Tools such as Burp Suite, OWASP ZAP, sqlmap or custom scripts are welcome as long as they are used responsibly and within the agreed test window. Deliverables 1. A concise executive summary outlining overall risk. 2. A technical report for each vulnerability containing: steps to reproduce, affected endpoints, impact analysis and mitigation advice. 3. Proof-of-concept payloads or screenshots for critical findings. 4. A retest checklist so I can verify fixes later. Acceptance criteria • All three vulnerability categories are thoroughly checked. • False positives are removed; every issue is reproducible. • Reports are delivered in both PDF and editable format. • No disruption to live services during testing. Let me know your estimated timeline, required test access and any legal paperwork you need signed, and we can get started.
Project ID: 40502989
47 proposals
Remote project
Active 22 secs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
47 freelancers are bidding on average €149 EUR for this job

Hello, I can perform a comprehensive penetration test of your web application and provide a detailed, evidence-based security assessment. I’m Md Shofiur, a Certified Ethical Hacker with 10+ years of experience conducting web application and API penetration tests for organizations worldwide. My testing follows the OWASP Testing Guide and combines automated scanning with extensive manual validation to eliminate false positives and uncover business-logic flaws that scanners often miss. Assessment Focus: - SQL Injection (SQLi) - Cross-Site Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Authentication and authorization weaknesses - API security issues - Session management flaws - Server-side security misconfigurations Methodology & Tools: Burp Suite Pro, OWASP ZAP, Nmap, custom testing scripts, and manual exploitation techniques where appropriate. Deliverables: - Executive summary with overall risk posture - Detailed technical report with reproduction steps, impact analysis, and remediation guidance - Proof-of-concept screenshots and payloads for verified findings - Retest checklist for future validation - Reports provided in PDF and editable format Before providing a final estimate, could you share: - Technology stack - Number of applications/domains in scope - Whether authenticated testing is required - Availability of a staging environment I’m available to start immediately and can work under NDA if required. Best regards, Md Shofiur
€140 EUR in 7 days
7.5
7.5

As a seasoned ethical hacker, I've dedicated the last 7+ years of my career towards breaking into systems just as a malicious hacker would. For you, this means I am able to think beyond the checkbox auditor mentality and approach your public-facing web applications from the perspective of real-world attackers. By employing methodologies listed in OWASP testing guide and tools such as Burp Suite and SQLMap, I can assure you thorough, meticulous scrutiny of your stack. The allure of your project is in its proactivity - finding security flaws before they are exploited. It's exactly what I believe in and what my clients most value. Not only do I bring with me an impressive collection of certifications including CEH, OSCP and CISSP, but also a proven track record of discovering critical zero-days that may have cost clients significantly more than my fee. Additionally, my experience with conducting Web & API penetration testing (OWASP Top 10 and beyond), red teaming, vulnerability assessments, cloud security reviews (AWS, Azure, GCP), and secure code review further validate my dedication to digital security.
€200 EUR in 7 days
5.5
5.5

Hi, I'm a Cyber Security Researcher with practical experience gained through playing CTFs (Capture The Flag), engaging in Bug Bounties, and working as a Pentester. Notice: Don’t ask me to hack something u don’t OWN What I can do for you: Web/API/Android (OWASP TOP 10) Pentesting: You can also get this service from here: https://www.freelancer.com/service/web_security/web-app-penetration-test-owasp-top Lets Chat…
€140 EUR in 7 days
4.9
4.9

Hello, I am a Cybersecurity Consultant and Ethical Hacker with experience in conducting comprehensive web application penetration tests following OWASP Testing Guide and industry best practices. I can perform a thorough assessment of your public-facing applications, including front-end, back-end, APIs, authentication mechanisms, and server-side components. Special focus will be placed on identifying and validating SQL Injection, XSS, and CSRF vulnerabilities, along with any additional security weaknesses discovered during manual testing. My approach combines Burp Suite Professional, OWASP ZAP, custom testing methodologies, and manual verification to eliminate false positives and uncover business logic and access control flaws that automated scanners often miss. Deliverables will include: • Executive risk summary • Detailed technical findings with reproduction steps • Impact assessment and remediation recommendations • Proof-of-concept screenshots/payloads • Retest checklist for future validation • Reports in PDF and editable formats I can provide an estimated timeline after reviewing the application scope and required test access. I am also comfortable signing NDA and other legal documentation before engagement. I look forward to discussing your requirements. Best regards, Kajal Majhi Cybersecurity & Digital Forensic Specialist
€250 EUR in 7 days
5.0
5.0

Hi, You need a thorough Web Application Vulnerability Assessment that identifies real security risks, not just automated scanner results. I am a Certified Ethical Hacker (CEH) and penetration tester with experience performing OWASP-based security assessments against web applications, APIs, authentication systems, and server infrastructure. My methodology combines automated scanning with manual verification to eliminate false positives and uncover vulnerabilities often missed by automated tools. My testing covers: • SQL Injection (SQLi) • Cross-Site Scripting (XSS) • Cross-Site Request Forgery (CSRF) • Broken Access Control / IDOR • Authentication & Session Management Issues • Security Misconfigurations • API Security Testing • Business Logic Flaws Tools & Methodology: • Burp Suite • OWASP ZAP • SQLMap • Nmap • Manual Exploitation & Validation • OWASP Testing Guide Deliverables: ✓ Executive Summary ✓ Detailed Technical Report ✓ Proof-of-Concepts (PoCs) ✓ Risk Ratings ✓ Remediation Recommendations Before starting, I'd like to know: 1. How many applications/domains are in scope? 2. Is authenticated testing required? 3. Will testing be performed against production or staging? I can start immediately after receiving scope details and authorization. I am also comfortable signing an NDA if required. I look forward to helping secure your application and providing actionable findings. Best Regards, Ammar Khan CEH | Penetration Tester
€250 EUR in 7 days
4.2
4.2

Hello there, I can run an authorized OWASP-style assessment of your web apps covering front end, backend, APIs, SQLi, XSS, CSRF, access control, and business-logic issues. I’ll validate findings manually, avoid service disruption, and deliver a clear executive summary plus technical report with reproducible steps, screenshots/PoCs, impact, fixes, and a retest checklist.
€126 EUR in 1 day
3.9
3.9

Hello, I can perform a comprehensive OWASP-based penetration test of your public-facing web applications, covering frontend, backend, APIs, authentication, authorization, and server-side components. My approach combines automated scanning (Burp Suite, OWASP ZAP, sqlmap) with manual validation to remove false positives and identify business-logic and access-control weaknesses that scanners often miss. Key focus areas: • SQL Injection (SQLi) • Cross-Site Scripting (XSS) • Cross-Site Request Forgery (CSRF) • Authentication & Authorization flaws • API Security issues • Session management weaknesses Deliverables: 1. Executive Summary with overall risk rating 2. Detailed vulnerability report including: * Affected endpoints * Reproduction steps * Impact assessment * Mitigation recommendations 3. PoC payloads/screenshots for critical findings 4. Retest checklist for future verification 5. Reports in PDF and editable format All findings will be manually verified and fully reproducible. Testing will be conducted responsibly to avoid disruption to live services. Estimated timeline: 3–5 days (depending on scope and number of applications). I am ready to sign an NDA and can discuss required access, testing windows, and engagement rules before starting. Thank you for your consideration.
€140 EUR in 7 days
3.8
3.8

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive web application penetration test focused on identifying and validating real-world vulnerabilities. Approach • Full assessment aligned with the OWASP Testing Guide and PTES methodology • Manual + automated testing of web applications, APIs, and server-side components • Deep focus on SQL Injection, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF) • Additional testing for authentication, authorization, session management, IDOR, business logic flaws, and security misconfigurations • Validation of all findings to eliminate false positives Tools Burp Suite, OWASP ZAP, SQLMap, Nmap, Nuclei, and custom scripts Deliverables • Executive Summary highlighting overall security posture and risk • Detailed technical report with CVSS ratings, affected endpoints, reproduction steps, impact analysis, and mitigation guidance • PoC evidence including screenshots, payloads, and request/response logs for critical findings • Retest checklist to assist with future remediation validation • Reports in PDF and editable format Timeline & Requirements • Estimated duration: 5–7 business days • Requirements: Target URLs, test credentials (if available), scope confirmation, and Rules of Engagement/NDA if required We ensure non-disruptive testing, responsible disclosure, and fully reproducible findings. Ready to start immediately once scope is finalized.
€250 EUR in 7 days
3.6
3.6

Hi there, This project instantly caught my eye, so I had to reach out. I see you looking for a seasoned ethical hacker to conduct a thorough vulnerability assessment on your web applications, focusing on vulnerabilities like SQL injection, XSS, and CSRF. I specialize in identifying web application vulnerabilities and have a proven track record of helping businesses improve their security posture. I can provide samples of successful projects upon request. Based on what you mentioned, here is how we would approach the project: - Conduct automated scanning followed by manual validation - Utilize tools like Burp Suite and OWASP ZAP - Deliver an executive summary, technical reports, proof-of-concept payloads, and a retest checklist Rest assured, we will ensure clear communication and deliver a seamless, user-focused solution optimized for performance. Best Regards, XRProConnect
€150 EUR in 7 days
3.0
3.0

BEFORE YOU HIRE ANYONE, GIVE ME 30 SECONDS TO SHOW YOU WHY I'M DIFFERENT. I recently conducted a web app vulnerability assessment for a tech firm, identifying critical SQL injection flaws. This led to a 50% decrease in potential security breaches. Briefly, I bring 5+ years of ethical hacking experience, specializing in web application security testing. My track record includes uncovering and resolving complex vulnerabilities similar to what you seek. I understand your need for a comprehensive assessment to uncover vulnerabilities like SQL injection, XSS, and CSRF. I will follow OWASP Testing Guide principles, using tools like Burp Suite and custom scripts responsibly. The difference between an average result and an exceptional one is usually decided before the work even begins. Regards, Patrick
€150 EUR in 7 days
2.6
2.6

✔ Hi there, I can perform a structured security assessment of your public-facing web applications following OWASP Testing Guide principles, focusing on SQL injection, XSS, CSRF, and deeper business-logic vulnerabilities, and deliver a clear, reproducible report with proof-of-concept evidence, risk analysis, and remediation guidance without impacting live services. Best Regard, John C.
€140 EUR in 7 days
0.0
0.0

Hello I can carry out a structured, OWASP-aligned security assessment of your public-facing web applications with a strong focus on SQL injection, XSS, and CSRF, while also extending the review to business logic and access control weaknesses that automated scanners typically miss. My approach combines automated tooling (Burp Suite / OWASP ZAP / sqlmap where appropriate) with manual validation to ensure every finding is real, reproducible, and clearly demonstrated. Each vulnerability will be documented with step-by-step reproduction, affected endpoints, impact explanation, and clear evidence such as PoC payload behavior or screenshots. You’ll also receive a concise executive summary plus a retest checklist so fixes can be verified easily later. I’m ready to start as soon as access and scope details are shared, along with any required NDA or authorization paperwork. Portfolio: https://www.freelancer.pk/u/salahuddin1973 Naufal
€100 EUR in 15 days
0.0
0.0

BEFORE YOU HIRE ANYONE, GIVE ME 30 SECONDS TO SHOW YOU WHY I'M DIFFERENT. I am a perfect fit for your project as I have recently helped someone achieve the same goal you are looking to achieve. I've conducted comprehensive vulnerability assessments for web applications, ensuring robust security measures for service businesses. Understanding your need for a meticulous assessment, I will focus on SQL injection, Cross-site scripting, and Cross-site request forgery vulnerabilities, following OWASP Testing Guide principles. I would love to chat about your project, the worst that can happen is you walk away with a free consultation. Regards, Clinton.
€100 EUR in 7 days
0.0
0.0

"Hi, Let's built the future I understand the critical importance of ensuring the security of your public-facing web applications to prevent potential attacks. Identifying vulnerabilities such as SQL injection, Cross-site scripting, and Cross-site request forgery is key to safeguarding your systems and data integrity. By conducting a thorough assessment covering the full web stack and using tools like Burp Suite and OWASP ZAP, we can uncover vulnerabilities beyond automated scans, providing you with clear, actionable insights. Having expertise in ethical hacking and security assessments, I have successfully conducted similar vulnerability assessments in the past, ensuring comprehensive testing and detailed reporting for each identified issue. My approach aligns with OWASP Testing Guide principles, focusing on delivering concise executive summaries, technical reports, proof-of-concept payloads, and retest checklists to support your risk mitigation efforts. To kick off this project, I would like to discuss your estimated timeline, required test access, and any legal requirements to ensure a smooth testing process. I'd be happy to discuss the details, review your requirements, and recommend the most practical path forward before development begins. Best regards, Hasib"
€30 EUR in 7 days
0.0
0.0

New Opportunity is Coming! I understand the critical importance of securing your public-facing web applications from potential threats. Identifying vulnerabilities before attackers exploit them is crucial for safeguarding your business data and maintaining trust with your users. By conducting a comprehensive assessment covering the full web stack and focusing on high-priority findings like SQL injection, XSS, and CSRF, we can proactively address potential weaknesses and strengthen your overall security posture. With over 6 years of experience in building secure web products and implementing robust security measures, I have successfully conducted similar vulnerability assessments for various clients. By following OWASP Testing Guide principles and utilizing tools like Burp Suite and OWASP ZAP responsibly, we can ensure a thorough evaluation of your applications' security. To proceed, I would like to understand more about your current infrastructure, access requirements for testing, and any legal documentation needed to initiate the assessment. I am committed to delivering detailed reports, actionable insights, and proof-of-concept payloads to help you mitigate risks effectively. I'd be happy to discuss the details, review your requirements, and recommend the most practical path forward before development begins. Best regards, Sai
€30 EUR in 7 days
0.0
0.0

⭐⭐⭐⭐⭐ Identify Vulnerabilities in Your Web Applications Effectively ❇️ Hi My Friend, I hope you're doing well. I've reviewed your project requirements and see you're looking for an ethical hacker to identify vulnerabilities in your web applications. Look no further; Zohaib is here to help you! My team has successfully completed over 50 similar projects for ethical hacking and vulnerability assessments. I will use a combination of automated tools and manual validation to ensure we find every weakness. ➡️ Why Me? I can easily identify vulnerabilities in your web applications as I have 5 years of experience in ethical hacking, specializing in SQL injection, XSS, and CSRF. My expertise includes using tools like Burp Suite, OWASP ZAP, and sqlmap for thorough assessments. I also have a strong grip on web application security principles, ensuring a comprehensive approach to your project. ➡️ Let's have a quick chat to discuss your project in detail and let me show you samples of my previous work. I'm looking forward to discussing this with you in our chat. ➡️ Skills & Experience: ✅ Ethical Hacking ✅ Vulnerability Assessment ✅ SQL Injection Testing ✅ XSS Testing ✅ CSRF Testing ✅ Manual Testing ✅ Automated Scanning ✅ OWASP Testing Guide ✅ Reporting & Documentation ✅ Risk Analysis ✅ Security Protocols ✅ Web Application Security Waiting for your response! Best Regards, Zohaib
€150 EUR in 2 days
0.0
0.0

Hi, I have experience conducting web application security assessments following OWASP Testing Guide methodologies, combining automated scanning with manual verification to eliminate false positives and uncover business-logic flaws that scanners often miss. My assessment will cover: ✓ SQL Injection (SQLi) ✓ Cross-Site Scripting (XSS) ✓ Cross-Site Request Forgery (CSRF) ✓ Authentication & Session Management ✓ Access Control & Privilege Escalation ✓ API Security Testing ✓ Business Logic Vulnerabilities ✓ Security Misconfigurations Tools I typically use include Burp Suite Pro, OWASP ZAP, sqlmap, browser-based testing, and custom validation scripts where appropriate. All testing will be performed responsibly within the agreed scope and without disrupting production services. Before starting, I would need the target URLs, testing scope, authorization for testing, and any IP whitelisting requirements. Estimated timeline: 2–5 days depending on application size and API coverage. Best regards, Microlent Team
€140 EUR in 7 days
2.4
2.4

Hello! This is exactly the kind of structured security assessment I handle—OWASP-based web application testing focused on real exploitability, not just scanner noise. I can perform a full black-box + grey-box penetration test across your frontend, backend, and APIs, manually validating SQLi, XSS, CSRF, and also checking deeper issues like authentication bypass, IDOR, and business logic flaws. Every finding will include reproducible steps, impact analysis, and clear PoC evidence (Burp Suite workflows, payloads, screenshots), filtered to remove false positives. My approach is methodical: initial recon + automated baseline scan, followed by deep manual testing of access control and input handling, especially around API endpoints and session flows. I also map findings directly to OWASP Top 10 so you get a clean, audit-ready report. Before starting, I’ll align with you on scope boundaries, test windows, and access method to ensure zero disruption to production systems, and I can provide NDA/authorization documentation if needed. I’d be happy to review your applications and help you close security gaps before they become real incidents. Thanks!
€80 EUR in 3 days
0.0
0.0

GIVE ME 30 SECONDS TO SHOW YOU WHY I AM DIFFERENT. I recently conducted a web app vulnerability assessment for a similar client, ensuring comprehensive coverage of the full web stack. The outcome was a detailed report highlighting critical vulnerabilities with clear evidence and actionable mitigation strategies. - Delivering a concise executive summary and detailed technical reports for each vulnerability. - Completing the work ahead of the deadline for refinement, testing, and adjustments. I understand the critical importance of thoroughly checking for SQL injection, XSS, and CSRF vulnerabilities, as outlined in your project requirements. One common risk in such projects is overlooking manual validation, which can lead to missed critical issues. Could you please provide more details on the expected test access and specific legal paperwork needed for this assessment? Regards, Joshua Jaime Saunders
€100 EUR in 7 days
0.4
0.4

I feel that our team would be the right fit for your project since we have plenty of experience in delivering complex web and mobile apps. We understand the importance of a clean user-friendly UI for high-end customers. We are prepared to conduct a comprehensive web app vulnerability assessment covering the full web stack, focusing on SQL injection, XSS, and CSRF, following OWASP Testing Guide principles. Our deliverables will include an executive summary, technical reports for each vulnerability, proof-of-concept payloads, and a retest checklist for verification. I'd love to chat about your project and how we can help you walk away with a free consultation. Regards, Nabeel Ismail
€100 EUR in 7 days
0.0
0.0

Žilina, Slovakia
Member since Nov 26, 2025
$30-250 USD
₹100-400 INR / hour
$50-100 USD
₹750-1250 INR / hour
$250-750 USD
₹1500-12500 INR
₹100-400 INR / hour
$14-100 NZD
$30-250 CAD
₹8000-10000 INR
$250-750 USD
₹12500-37500 INR
$30-250 USD
$10-30 AUD
$750-1500 USD
$10-30 USD
$75-150 USD
$10-30 USD
₹12500-37500 INR
$30-250 USD
$30-250 USD