
Closed
Posted
Paid on delivery
I need an expert to identify any Cross-Site Scripting (XSS) vulnerabilities on my personal blog. The primary goal of this project is: The goal of this challenge is to find XSS attacks that are not blocked by the WAF. Based on your findings, we are going to improve our filtering rules. You may choose between these three options: Option 1: Call the alert() function in this page Use cross-site scripting to display the value of the JavaScript variable myvar in the browser using JavaScript's alert() function. The variable myvar is randomly set at the beginning of the page source. Option 2: Steal the BUGBOUNTY cookie Use cross-site scripting to steal the cookie named "BUGBOUNTY". This cookie is randomly set and resent by the backend every time you request this webpage. To solve the challenge, inject JavaScript code in the value of the query parameter inject such that, as soon as this page loads, the most recent cookie is sent to a website of your choice. - Extensive knowledge in web security, particularly in XSS vulnerabilities. - Proven experience in vulnerability assessment on blogs or personal sites. - Ability to deliver comprehensive reports detailing identified vulnerabilities and recommendations for remediation.
Project ID: 38736432
36 proposals
Remote project
Active 2 yrs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
36 freelancers are bidding on average $150 USD for this job

With a rigorous background in web security and vulnerability assessment on blogs, I, Naumeer Anwer, am keen on delving into identifying Cross-Site Scripting (XSS) vulnerabilities on your personal blog. Over the years, I've had the fortune of working with influential brands - an exposure that has safeguarded my expertise in finding unconventional XSS attacks not blocked by WAFs - mirroring your exact requirement. Aside from just pinpointing vulnerabilities, my focus is always on providing comprehensive reports to my clients that contain a full analysis of the identified threats along with robust recommendations for fortified website protection strategies. My adaptive nature and knack for the subject assure you to take care of all your XSS concerns, irrespective of the scale or specificity. Furthermore, working with me means gaining access to an extensive array of skills including PHP proficiency alongside my strong suit in WordPress. This would undoubtedly expedite the process of applying necessary renovations once we've curated our list of your specific needs. Don't hesitate to reach out so we can begin this enriching journey together towards a safer digital environment for your personal blog!
$250 USD in 7 days
8.5
8.5

Dear Ahmed S., This project seems a very fit work for me. I have done quite the same work some time ago. I would like to grab this opportunity and will work till you get 100% satisfied with my work. I have many years of experience with PHP, Web Security, WordPress, Computer Security, Internet Security Please initiate chat and discuss your requirement in details. Regards
$30 USD in 2 days
7.4
7.4

Hi, I have experience working on similar projects and am confident in delivering a solution that meets your goals. Please check my profile for more details about my background and past work. I’m available to start immediately and would be happy to discuss specifics over chat. Looking forward to working together!
$99 USD in 7 days
6.6
6.6

Hello, Greetings of the day!! I have understood your requirement in the project that **you need to identify XSS vulnerabilities in your personal blog that bypass your WAF and you want to improve your filtering rules based on the findings.** I have 10+ years of experience in Nodejs, Python, AI/ML, Web Designing/Development, HTML5, PHP, E-commerce, and Mobile Application development using Ionic, React Native, and Flutter, etc. I am able to do this work as I have the necessary knowledge. So I think I can handle your requirement decently. If you need any clarifications on my bid, please let's talk about it. I hope to hear from you soon so we can get things done. Thanking You, Regards, Priyank Bhargava
$130 USD in 7 days
6.4
6.4

Hey there, I have been in Cyber Security for years. I had conducted tons of Vulnerability Assessment and Penetration Testing projects. I can identify any XSS vulnerabilities in your personal blog. I have the required skills and experience. Regards!
$250 USD in 7 days
6.0
6.0

Hello Ahmed, I am an experienced web security expert with a strong background in identifying Cross-Site Scripting (XSS) vulnerabilities. For your personal blog, I can conduct a thorough assessment to pinpoint any XSS vulnerabilities that may bypass the Web Application Firewall (WAF). By executing simulated attacks like calling the alert() function or attempting to steal the BUGBOUNTY cookie, we can analyze the effectiveness of your current security measures and enhance your filtering rules accordingly. Would you be interested in a FREE demo to showcase how I can improve the security of your blog? Please reply to this message so we can discuss this project further. I am genuinely excited about the opportunity to work on this critical aspect of your website's security. Best regards, Sufiyan
$80 USD in 7 days
5.0
5.0

Hi, I'm a Cyber Security Researcher with practical experience gained through playing CTFs (Capture The Flag), engaging in Bug Bounties, and working as a Pentester. What I can do for you: Web/API (OWASP TOP 10) Pentesting: - Web Applications like WordPress, CMS, CRM, LMS, Full stack, etc. You can also get this service from here: https://www.freelancer.com/service/web_security/web-app-penetration-test-owasp-top Lets Chat…
$200 USD in 7 days
4.7
4.7

Good morning. I have been a system administrator and cybersecurity analyst for 18 years. I currently manage about 60 servers with all kinds of web applications running. I can help you solve the problem. Regards.
$250 USD in 7 days
3.5
3.5

HEY THERE, With my extensive knowledge and years of experience specifically in web security, I have the expertise required to assist you in identifying and remedying any Cross-Site Scripting (XSS) vulnerabilities on your personal blog. Over the years, I've completed numerous projects involving vulnerability assessment for blogs and personal sites, delivering detailed reports on identified vulnerabilities along with practical recommendations for improvements. Rest assured that I will provide you with a comprehensive analysis aimed at enhancing your filtering rules, focusing on XSS attacks that can bypass WAF. In addition to my skills in Computer Security and Web Security, I am a versatile full-stack developer proficient in various web development technologies that include languages such as JavaScript TypeScript, NodeJS, Express, MEAN+MERN stack, and more. This fluency within the realm of web technologies particularly lends itself to solving your problem where it requires intricate manipulation of JavaScript variables and cookie values to orchestrate cross-site scripting attacks. CHOOSING ME IS THE BEST DECISION YOU WILL EVER MAKE SIR...
$150 USD in 2 days
2.4
2.4

Hello, I am interested in your project. Look at my profile. I am expert in these tasks that mention in your project description. I have more than 15 years of work experience. Time and budget will be decided after detailed discussion on chat or call. I am hoping for your positive response. Regards Pragnesh Tavadia
$30 USD in 1 day
2.6
2.6

Hello, I have briefly read the description of your project, and I can deliver as per the requirements. However, I need us to clarify the details, deadline, and budget. I am reaching out to see whether the opportunity is still available. If the job is no longer available, I’d appreciate it if you would put my name forward for any similar opportunities in the future. Thank you for your time; I look forward to hearing from you soon, Best Wishes, Kevin M
$140 USD in 7 days
2.2
2.2

Hi, I hope you are doing great. I’m excited to apply for the XSS Vulnerability Assessment on your personal blog. With a solid background in web security and hands-on experience in identifying vulnerabilities, I’m ready to assist you in uncovering and addressing any XSS issues. I recognize the urgency of your project, particularly the need to identify XSS attacks that the WAF doesn’t block. I can efficiently carry out both options you mentioned: using the "alert()" function to display the variable or capturing the “BUGBOUNTY” cookie through JavaScript injection. My strategy will involve a comprehensive analysis of your blog to pinpoint XSS vulnerabilities, employing both methods to ensure thorough coverage. I will provide a detailed report of my findings, along with suggestions for enhancing your filtering rules. I have a proven history in vulnerability assessments and am dedicated to delivering clear, actionable insights. I look forward to the opportunity to help strengthen your blog's security. Thank you for considering my proposal! Best Regards, Zainab N.
$140 USD in 7 days
0.8
0.8

Hi Mate! Thank you for the job posting! I read your project description carefully and got interested. I am skilled in WordPress, Web Security, Computer Security, Internet Security and PHP. I don't like ramble. I am ready to start working now and will deliver the best result asap. Best regards Zeljko
$200 USD in 7 days
0.0
0.0

Hi, I would like to grab this opportunity and will work till you get 100% satisfied with my work. I have many years of experience on PHP, Web Security, WordPress, Computer Security, Internet Security Please come over chat and discuss your requirement in a detailed way. Thank You
$30 USD in 7 days
0.0
0.0

Hi. Nice to meet you. I'm Roman, a proficient web technologies expert specialising in web security, who is more than capable of conducting a deep-dive vulnerability assessment on your blog to identify any Cross-Site Scripting (XSS) vulnerabilities. My extensive knowledge in this area, combined with my proven experience in conducting similar assessments for blogs and personal sites, particularly make me the best fit for your project. I've managed databases with SQL, utilized Python for data extraction and analysis, which strategically aligns with XSS vulnerability assessment and identifying such attacks. What sets me apart is my ability to go the extra mile and deliver comprehensive reports detailing identified vulnerabilities and strategic recommendations for remediation. I don't believe in just pointing out vulnerabilities but also aim to provide actionable solutions that can significantly improve your site's web application filtering rules to mitigate XSS threats. In sum, my deep understanding of secure code practices, familiarity with different backend and frontend frameworks coupled with a continuous drive to innovate makes me the ideal hire for this project. Don't take chances on your blog's security. Connect with me so we can discuss further about how I can help you achieve the goal of this challenge: find XSS attacks that are not blocked by WAF, report them extensively and help you upgrade your filtering rules. Let's enhance your blog's security together!
$140 USD in 7 days
0.3
0.3

Hello! With 3 years of experience as a penetration tester and extensive expertise in XSS vulnerabilities, I can help you identify and exploit any Cross-Site Scripting (XSS) weaknesses in your blog, even bypassing WAF protection. My bug bounty experience has sharpened my skills in real-world scenarios, making me adept at detecting vulnerabilities others may overlook. For this project, I’ll assess both alert function vulnerabilities and cookie theft via JavaScript injection, providing a thorough report with actionable recommendations to improve your site’s security. Let's secure your platform effectively!
$80 USD in 4 days
0.0
0.0

Hi, I'm a Cybersecurity Engineer also a pentester, bug bounty hunter. I can help you with pentesting your site. Hope to collaborate with you.
$250 USD in 7 days
0.6
0.6

I will help you identify any Cross-Site Scripting (XSS) vulnerabilities on your personal blog. I am a Professional Bug Bounty Hunter From HackerOne and Bugcrowd. Please check My portfolio. I hope you work with me. I will be waiting for you response Regards.
$140 USD in 7 days
0.0
0.0

I am Omar, a web security specialist with extensive experience in identifying and addressing XSS vulnerabilities in WordPress and PHP. I will evaluate your blog to uncover any vulnerabilities not protected by the WAF using appropriate security testing tools. I will prepare a comprehensive report outlining the discovered vulnerabilities along with precise recommendations for improving security. I look forward to contributing to the enhancement of your blog's security.
$140 USD in 7 days
0.0
0.0

Cyber Security and Ethical Hacking | CFSS (ISO 9001 2015 CERTIFIED) March 2024 – April 2024 – Vulnerabilities scanning: scan on the Metasploitable machine using Nessus.| Wayback Machine : retrieving sensitive data from the Wayback Machine – Establish a connection to a local area network (LAN) via Wi-Fi. | Utilizing the NMAP tool to determine the number of devices currently connected to the LAN. – John the Ripper : password cracking tool illustrating how a weak password can be compromised. – Develop an security incident response plan to address the given situation. | in-depth explanation of the distinctions between WEP, WPA, WPA2, and WPA3 in the context of wireless networking. Mine Internship
$180 USD in 7 days
0.0
0.0

Cairo, Egypt
Member since Mar 22, 2024
$10-30 USD
$10-30 USD
$250-750 USD
$10000-20000 USD
$15-25 USD / hour
$10-30 USD
$10-30 USD
₹100-400 INR / hour
€8-60 EUR
₹1500-12500 INR
$10-30 USD
$2-8 USD / hour
$1500-3000 CAD
₹600-1500 INR
$250-750 USD
£10-15 GBP / hour
₹1500-12500 INR
$30-250 AUD
₹100-400 INR / hour
$12-30 SGD
₹1000-2000 INR
₹37500-75000 INR