
Closed
Posted
Paid on delivery
I need an experienced ethical hacker to run a full-scope penetration test on our production mobile app, which is released on both iOS and Android. The engagement should mimic real-world attack techniques, covering client-side and back-end interactions, with a clear focus on the OWASP Mobile Top 10 and any platform-specific abuses you typically see on Apple and Google ecosystems. Please perform static and dynamic analysis, investigate authentication flows, data storage, transport encryption, third-party SDK exposure, and any jailbreak/root bypasses that could threaten user data or server resources. Throughout the test, keep detailed notes; I will ask for a concise executive summary followed by a technical report that includes: • A prioritized list of discovered vulnerabilities with CVSS (or comparable) severity ratings • Proof-of-concept steps or scripts to reproduce each finding • Practical remediation guidance that our development team can act on quickly All testing must remain within the agreed scope and comply with platform terms so our store listings stay unaffected. Let me know the estimated duration and the tools you prefer—Burp Suite, MobSF, Frida, or your own setup—so I can arrange the necessary test accounts and API keys before you begin.
Project ID: 40540238
106 proposals
Remote project
Active 2 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
106 freelancers are bidding on average $488 USD for this job

Hi, I can perform a full-scope mobile pentest for both iOS and Android, focusing on the areas most likely to expose real risk: authentication and session handling, local data exposure, weak TLS, SDK leakage, and jailbreak/root bypasses that could impact backend resources. My approach is to map the app’s login flow, token storage, request paths, and sensitive screens, then validate those findings with static and dynamic analysis. I’ll test against OWASP Mobile Top 10, review third-party SDK behavior, and verify protections against modified devices and intercepted traffic. Initial focus: - App attack surface mapping - Auth and session flow review - Local storage and transport checks - SDK and backend interaction review - Root/jailbreak bypass testing I can deliver a concise executive summary and a technical report with severity ratings, reproduction steps, and remediation guidance. Timeline: I can start quickly and share initial findings early in the engagement, with the final report delivered after testing is complete. If helpful, I’d be glad to discuss scope further. Should the assessment include only authenticated user roles, or also admin/support functions if available?
$287 USD in 12 days
9.5
9.5

Hi I can perform a full-scope, authorized mobile penetration test for your iOS and Android production app with focus on OWASP Mobile Top 10, client-side risks, and backend API interaction security. I have experience with mobile security testing, static and dynamic analysis, Burp Suite, MobSF, Frida, objection, JADX, Android Studio, Xcode tools, API testing, authentication review, and secure storage assessment. The main technical problem is that mobile apps often expose risk across several layers at once, including weak token handling, insecure local storage, broken transport protection, SDK leakage, and backend authorization gaps. My approach would be to test within the agreed scope, review app binaries and runtime behavior, inspect API traffic, validate authentication/session flows, and assess jailbreak/root detection and bypass resistance. I would also check third-party SDK exposure, TLS configuration, sensitive data handling, logging behavior, permission usage, and platform-specific weaknesses for both Apple and Google ecosystems. All findings would be documented with severity ratings, business impact, reproducible proof-of-concept steps, and practical remediation guidance for your development team. I would keep testing controlled and compliant so production systems, users, and store listings are not disrupted. The final deliverables would include a concise executive summary, a detailed technical report, and clear prioritized fixes. Thanks, Hercules
$500 USD in 7 days
6.6
6.6

Hello, I'm Md Shofiur, a Certified Ethical Hacker and CEO of Pentest Testing Corp. With 10+ years of experience and thousands of successful penetration tests completed for organizations worldwide, I can perform a comprehensive security assessment of your iOS and Android application. My testing follows the OWASP Mobile Top 10 and includes static and dynamic analysis, authentication and authorization testing, insecure data storage, transport encryption, API security, third-party SDK assessment, jailbreak/root detection bypass validation, client-side reverse engineering, and platform-specific attack scenarios. I use Burp Suite Pro, MobSF, Frida, Objection, JADX, apktool, Ghidra, and platform-specific tooling to simulate realistic attacks while staying within the agreed scope. You'll receive an executive summary and a detailed technical report containing CVSS-rated findings, proof-of-concept steps, supporting evidence, risk impact, and practical remediation guidance for your development team. Estimated duration: 5-7 business days, depending on application complexity. A few questions: • Is a staging environment available, or should testing be conducted directly against production with your approval? • Can you provide APK/IPA files, test accounts, API documentation, and any required API keys? • Are there any features or integrations you want prioritized during the assessment? I look forward to helping secure your mobile application. Thanks Shofiur
$750 USD in 7 days
6.7
6.7

Hello, Your requirement for conducting a full-scope penetration test on your iOS and Android mobile application aligns perfectly with our expertise at Doomshell Software Pvt. Ltd. We specialize in application security assessments, mobile penetration testing, API security validation, and vulnerability analysis following OWASP security standards. We can support you with: ✔ Comprehensive OWASP Mobile Top 10 security assessment ✔ Static and dynamic analysis of Android and iOS applications ✔ Authentication, authorization, and session management testing ✔ API and backend security validation against real-world attack scenarios ✔ Data storage, encryption, and secure communication reviews ✔ Root/jailbreak detection and bypass assessment ✔ Third-party SDK and dependency security analysis ✔ Detailed executive summary and technical report with CVSS-based severity ratings, PoCs, and remediation guidance Our approach: ✔ Define and validate the testing scope to ensure compliance and zero impact on production services ✔ Perform structured security assessments using tools such as Burp Suite, MobSF, Frida, and manual testing techniques ✔ Prioritize findings based on risk and business impact ✔ Deliver actionable remediation recommendations for rapid resolution Quick questions: 1. Are test accounts and API documentation available for authenticated testing? 2. Would you like the assessment to include API rate-limiting and business logic security testing? Regards.
$500 USD in 7 days
6.3
6.3

Hello there, Hope you are doing well I’d be happy to perform a comprehensive security assessment of your iOS and Android mobile applications. I have experience conducting authorized penetration testing following OWASP Mobile Top 10 guidelines, helping development teams identify and remediate security risks before they impact users. Scope of Testing Static and dynamic application security testing Authentication, authorization, and session management review Secure data storage and transport encryption analysis API and backend interaction testing Third-party SDK and dependency assessment Root/Jailbreak detection and bypass evaluation Client-side security, reverse engineering, and code protection review Business logic and common mobile attack vector assessment Deliverables Executive summary suitable for management Detailed technical report with prioritized findings CVSS severity ratings for each vulnerability Proof-of-concept steps to reproduce identified issues Clear remediation recommendations for your development team Retest support after fixes (if required) Thanks & Regards Dheeraj k.
$250 USD in 7 days
7.0
7.0

Hi, there. I have carefully reviewed the requirements for Mobile App Penetration Testing. Based on your goals, you are looking for a mobile experience that is not just functional, but seamless and responsive for your users. My team and I specialize in mobile app engineering with a focus on high-performance architecture. We have a proven track record of helping businesses in United States build mobile solutions that scale effectively across both iOS and Android. Whether we are leveraging Android, iOS Development, Mobile App Development for a native build or a cross-platform solution, our focus is on ensuring the interface is intuitive and the backend data handling is secure. We treat every app we build as a long-term asset. We avoid common pitfalls in mobile development such as memory leaks or poor UI responsiveness, ensuring your users have a smooth experience from their very first interaction. To help me provide a precise timeline for your development, I have one quick question: Are you aiming to launch on both platforms simultaneously, or are you prioritizing one (iOS or Android) for your initial market validation? Knowing this helps me determine the most efficient architectural path for your project. I am available for a discovery call to discuss your mobile roadmap whenever you are ready. Best regards Kausar and the Team
$350 USD in 3 days
6.4
6.4

Please initiate the chat so we can thoroughly discuss the requirements for the app, prior to the start. Happy to provide the final budget in chat. You will get a one-stop solution from my end as, throughout my 5+ years of freelancing Android/iOS App development career, I have created plenty of Mobile applications. I ensure to give the best quality app with good performance and responsive attractive UI and I have provided the clients with excellent results. I have expertise in Swift, React Native, Node.js, React.js, Angular, Laravel, and PHP. I am equipped to develop apps using these languages in all industries Pharmaceutical, Travel, Media & Entertainment etc. I also handle backend integrations for third-party collaborations on your systems. well versed in Mobile App Development in-App-Purchases, User Authentication, User Profile Creation, Location, Chat and Messaging, Map Integration, Payments, Social Media Account Integration, and many more to show. Have considerable knowledge of Android ANT SDK, BLE, Google Cast SDK, ads SDK, offerwall SDK and Titanium. I use libraries such as Sherlock Action Bar, OpenGL, Media Framework, and WebKit to build IoT integration app solutions. I am always interested in making long term professional relationships with my clients to ensure that every project becomes successful. So, if you hire me, I can assure you that you will not regret your decision. Best Regards Tejash J.
$500 USD in 7 days
5.8
5.8

hi, i have experience conducting mobile application penetration testing for both ios and android platforms, with a strong focus on owasp mobile top 10 risks and real world attack scenarios. i will perform a complete security assessment including static and dynamic analysis, authentication testing, api security review, local data storage checks, transport encryption validation, third party sdk assessment, and root or jailbreak bypass testing. all findings will be documented with severity ratings, proof of concept steps, and clear remediation guidance that your development team can quickly implement. can we schedule a quick meeting to discuss the project in detail. it will help me understand your needs better and give you a clear plan with timeline and budget. i will also share my portfolio during the chat. thanks. mughiraa
$500 USD in 7 days
5.2
5.2

Hello, I have 9+ years of experience in mobile application security, penetration testing, and digital forensics. I can perform a comprehensive security assessment of your Android and iOS applications using a combination of manual testing and industry-standard tools including Burp Suite Pro, MobSF, Frida, JADX, APKTool, and platform-specific analysis techniques. The assessment will cover the OWASP Mobile Top 10, static and dynamic analysis, authentication and session management, secure data storage, transport encryption, API security, third-party SDKs, certificate pinning, root/jailbreak bypass testing, and client-server interaction to simulate real-world attack scenarios. You'll receive a clear executive summary, a detailed technical report with CVSS-rated findings, proof-of-concept reproduction steps, and practical remediation guidance for your development team. Estimated duration: 7–9 days, depending on application complexity and scope. I work strictly within the authorized scope and ensure testing does not impact your App Store or Google Play listings.
$600 USD in 7 days
5.0
5.0

Hi, We have already completed similar mobile application security assessments and penetration testing for Android & iOS applications. I have attached our testing checklist/report format for your reference. Our security assessment covers: ✔ OWASP Mobile Top 10 compliance ✔ Static & Dynamic Analysis ✔ Authentication & Authorization testing ✔ API & Backend security validation ✔ Data storage & encryption review ✔ SSL/TLS & certificate pinning validation ✔ Third-party SDK assessment ✔ Root/Jailbreak detection & bypass testing ✔ Reverse engineering assessment ✔ Business logic & session management testing We use industry-standard tools including Burp Suite Pro, MobSF, Frida, Objection, JADX, APKTool, Wireshark, Charles Proxy, and custom scripts where required. Deliverables: ✔ Executive Summary for management ✔ Detailed technical report with CVSS severity ratings ✔ Proof-of-Concept reproduction steps ✔ Actionable remediation recommendations ✔ Retesting after fixes Our testing follows responsible disclosure and stays strictly within the agreed scope, ensuring no impact on your App Store or Google Play listings. Once you provide the test accounts, API documentation, and scope, we can begin immediately and complete the assessment within the agreed timeline. Best Regards, Sanjana Kumari
$750 USD in 7 days
5.1
5.1

I have over a decade of experience developing and testing Android and iOS applications, which I believe makes me the ideal candidate for your Mobile App Penetration Testing project. I've successfully completed 100+ projects, many of which involved conducting thorough security assessments on mobile apps. Throughout my career, I have stayed up to date with the latest security threats and attack techniques targeting both Apple and Google ecosystems, ensuring I can efficiently identify vulnerabilities that could jeopardize user data. My skills in using tools like Burp Suite, MobSF, Frida, and others make it possible to carry out static and dynamic analysis as well conduct in-depth investigations of authentication flows, data storage, third-party SDK exposure and more. Moreover, as a Full Stack Developer, I offer the additional benefit of providing practical suggestions for remediation actions to implement these findings into actionable steps that your development team can act on quickly. By entrusting me with this project, not only will you benefit from my extensive experience but also my commitment to securing your app effectively while keeping all our testing activity within agreed-upon scope - an essential factor to maintain your store listings unaffected. So let's work together and ensure your mobile app is fortified against any potential cyber threats!
$450 USD in 7 days
4.8
4.8

Hello, I’m a QA Engineer with 6+ years of experience in mobile application testing, API validation, and security-focused QA. I have extensive experience identifying authentication flaws, insecure data handling, API issues, and OWASP-related risks through structured testing. I can assist with validating your iOS and Android applications by reviewing authentication flows, session management, data storage, transport security, API behavior, third-party SDK integrations, and client-side security from a QA perspective. My deliverables include detailed reports with reproduction steps, severity ratings, screenshots, and practical remediation recommendations for your development team. I regularly work with tools such as Burp Suite, Postman, Charles Proxy, MobSF for static analysis, and Android/iOS debugging utilities to support authorized security assessments. You’ll receive: • Executive summary • Prioritized findings with severity • Reproduction steps and evidence • Actionable remediation recommendations I can begin immediately and work within your defined scope while maintaining clear communication throughout the engagement. Best regards, Zain Ul Hassan QA Engineer | Mobile Testing | 6+ Years Experience
$500 USD in 7 days
4.9
4.9

Hi, I've read your brief — "Mobile App Penetration Testing". This is squarely our wheelhouse at Global IT Vision: a polished cross-platform mobile app for iOS + Android with clean UX and a solid backend/API where needed. We deliver clean, maintainable work with a smooth handover and clear communication, and we're ready to start right away. — Muhammad Idrees / Global IT Vision Pvt. Ltd
$500 USD in 21 days
5.8
5.8

With my extensive experience in full stack development and a sharp expertise in iOS Development, I am confident in my ability to conduct a comprehensive and beneficial penetration test on your mobile app. I understand the absolute importance of uncovering vulnerabilities that pose serious threats to the security of your user data and server resources. My knowledge of testing tools such as Burp Suite, MobSF, and Frida will ensure thorough coverage. To optimize the testing process, I can leverage my proficiency with frontend technologies (including React Native) to investigate the client-side interactions on both iOS and Android platforms. The backend is equally as important, and my capabilities with Node.js, PHP, Laravel and databases like MySQL, PostgreSQL, MongoDB will allow me to examine the back-end interactions effectively. My familiarity with CMS platforms like WordPress and e-commerce platforms like Shopify and WooCommerce coincides with understanding authentication flows, data storage, and transport encryption.
$250 USD in 7 days
4.3
4.3

Hello, I can help perform a comprehensive penetration test of your iOS and Android applications, covering the OWASP Mobile Top 10, API security, authentication flows, data storage, transport security, third-party SDK risks, and root/jailbreak detection bypass assessments. My approach includes static and dynamic analysis using tools such as Burp Suite, MobSF, Frida, and platform-specific testing methodologies to simulate real-world attack scenarios while staying within the approved scope. Deliverables will include an executive summary, detailed technical report, CVSS-rated findings, proof-of-concept reproduction steps, and actionable remediation recommendations. Could you share whether the backend APIs and staging environment will also be included in scope? Best regards, Vijay
$500 USD in 15 days
4.1
4.1

As a seasoned full-stack developer with a strong focus on mobile app development and testing, I have gained substantial experience in ensuring the security, reliability, and performance of applications. Having worked on projects involving Android and iOS development, I am well-versed in both platform-specific threats and universally applicable vulnerabilities like the OWASP Mobile Top 10. Utilizing tools such as Burp Suite, MobSF, Frida, and my own setup, I can conduct both static and dynamic analysis of your mobile app. My detailed approach will include a comprehensive investigation into authentication flows, data storage, transport encryption, third-party SDK exposure, and potential jailbreak/root bypasses that could compromise user data or server resources. But it does not stop at identification. I'll provide you with an executive summary as well as a prioritized list of discovered vulnerabilities with CVSS severity ratings for quick action from your developers. My proficiency in building long-term relationships through quality work and dependable support means I will also provide practical remediation guidance to address the identified issues efficiently. With me at the helm of your Mobile App Penetration Testing project, you receive nothing but an all-rounded expertise and the dedication to ensure your app is safe and sound for your users.
$500 USD in 7 days
3.7
3.7

As an ethical hacker, I don't just penetrate but also protect - ensuring that your mobile app remains uncompromised, safe, and entirely compliant with platform terms. With a rich background in Customized python web Automation, Data mining and Extraction, AI Solutions, Full-Stack Web Development, and Mobile Application design such as yours, I would be the perfect fit for the job. I guarantee a highly detailed report outlining CVSS severity ratings for each vulnerability discovered along with organized proof-of-concept steps to reproduce each finding. Additionally, my practical remediation guidance will provide your team with clear actionable steps to quickly address any issue uncovered. With me, not only will your app be scrutinized against OWASP top 10 list as requested but also against any other probable threats unique to iOS and Android. Don't gamble on security; let's work together and ensure your users' data is always protected. Contact me today!
$250 USD in 1 day
3.4
3.4

Hey there! I'm really pumped about this opportunity! I recently led a project with similar challenges and nailed it. Drawing from my experience in Mobile App Development, Android, Testing / QA, Usability Testing, Mobile App Testing, Penetration Testing, iOS Development, Security, I’m ready to dive into your project. Please come over chat and discuss your requirement in a detailed way. Kind regards, Vishal Maharaj
$500 USD in 5 days
3.2
3.2

Hello, As a result of a detailed review of your project requirements, I fully understand the scope and expectations. I have experience performing security assessments for mobile applications and I'm available to start your project right now. I bring deep expertise in Penetration Testing, Mobile App Security, iOS Development, Android, Mobile App Testing, Testing/QA, and Security with over 10 years of experience. I can perform both static and dynamic analysis, evaluate authentication, secure data storage, transport encryption, third-party SDK exposure, and test against the OWASP Mobile Top 10 while documenting every finding with reproducible proof-of-concept steps and practical remediation guidance. Regarding your questions: • Estimated duration: approximately 5–7 days, depending on the application size and API scope. • Preferred tools: Burp Suite, MobSF, Frida, platform-native analysis tools, and other industry-standard utilities as needed for comprehensive testing. I have a quick question. • Will you provide test accounts with different user roles and access to a staging API, or should all testing be performed directly against the production environment within the approved scope? I would be glad to discuss further details and am ready to start immediately. Looking forward to hearing from you. Best regards, Carlos.
$250 USD in 7 days
3.0
3.0

Hello Having been involved in various aspects of software development for over 9 years, my team and I are equipped with the diverse skills and knowledgebase required to conduct a thorough and comprehensive mobile app penetration test. Our deep understanding of multiple programming languages like Python, Java, C++, and JavaScript aids us in performing static and dynamic analysis that encompasses intricate details such as authentication flows, data storage, transport encryption, third-party SDK exposure, jailbreak/root bypasses, and much more. Moreover, our proficiency in building apps for both iOS and Android platforms using Flutter serves as an added advantage. We have a broad range of testing strategies up our sleeves, which include employing tools like Burp Suite, MobSF, Frida or even our own setup rationally based on testing motives. For your project, we will ensure to make the necessary arrangements beforehand.
$400 USD in 3 days
3.7
3.7

Matawan, United States
Member since Feb 6, 2024
$250-750 USD
$30-250 USD
$250-750 USD
$30-250 USD
$250-750 USD
$250-750 USD
$30-250 USD
₹1500-12500 INR
$250-750 USD
$250-750 USD
₹12500-37500 INR
$750-1500 USD
$2-8 AUD / hour
$3000-5000 USD
₹1500-12500 INR
₹1500-12500 INR
$250-750 USD
$30-250 USD
$8-15 USD / hour
₹100-400 INR / hour
$250-750 USD
$750-1500 USD
$15-25 USD / hour
$10-30 USD