
Đã đóng
Đã đăng vào
Thanh toán khi bàn giao
I’m looking for an application-security specialist to give my production web app a thorough security treatment. The site is live, handles user data, and has grown faster than our in-house safeguards. I want someone who can step in, evaluate the current state of the code and infrastructure, discover weaknesses, and guide or implement the fixes. Scope • Focus strictly on the web-application layer—session handling, input validation, authentication, authorisation, business-logic flaws, and secure deployment practices. • I’m open to any mix of techniques you feel will uncover issues: manual code review, automated scanning, penetration testing, or a structured vulnerability assessment. If you can combine several approaches, even better. • Findings should be documented in a clear report that ranks each issue by severity, explains impact, and includes practical remediation steps. Deliverables 1. Kick-off call to outline the attack surface and agree on testing boundaries. 2. Security assessment (tools of your choice: Burp Suite, OWASP ZAP, custom scripts, etc.). 3. Written report with vulnerabilities, evidence, and remediation guidance. 4. Follow-up session to walk through results and clarify fixes. Acceptance Criteria • All high- and medium-severity issues reproduced and demonstrated. • Report delivered in PDF and editable format. • Recommendations aligned with OWASP Top 10 and industry best practices. If you have experience hardening large-scale web apps and can turn around a concise, actionable report, let’s talk and lock down timelines.
Mã dự án: 40258190
36 đề xuất
Dự án từ xa
Hoạt động 2 ngày trước
Thiết lập ngân sách và thời gian
Nhận thanh toán cho công việc
Phác thảo đề xuất của bạn
Miễn phí đăng ký và cháo giá cho công việc
36 freelancer chào giá trung bình £182 GBP cho công việc này

Hello, I’m Md Shofiur, a Certified Ethical Hacker (CEH) and CEO of Pentest Testing Corp. I specialize in production web-application security assessments—finding real, exploitable weaknesses and helping teams fix them quickly without disrupting a live product. I’ll start with a kick-off to map your attack surface and confirm testing boundaries. Then I’ll run a thorough web-layer assessment combining targeted manual testing, automated scanning, and (if appropriate) code review. I’ll focus on session handling, authentication/authorization, access control issues (including IDOR), input validation/injection, business-logic flaws, and secure deployment practices aligned with OWASP Top 10 and industry best practices. My tooling typically includes Burp Suite, OWASP ZAP, and custom scripts tailored to your stack. You’ll receive a clear, actionable report ranking issues by severity, with evidence/repro steps, impact, and prioritized remediation guidance. After delivery, I’ll walk your team through the findings and fixes, and can re-test to validate that high/medium issues are fully resolved. Reports can be provided in both PDF and an editable format. Please feel free to message me privately to discuss your project further. I look forward to the opportunity to work with you. Best regards, Md Shofiur CEO & Founder, Pentest Testing Corp.
£250 GBP trong 7 ngày
7,4
7,4

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
£250 GBP trong 3 ngày
6,5
6,5

With over a decade of experience in Network, Cybersecurity, and System Engineering, I am confident that I can provide your web application with the thorough security treatment it requires. My wide range of experiences working with both small and enterprise-sized companies have given me ample exposure to challenging situations where I had to thoroughly evaluate existing systems, uncover vulnerabilities, and provide concise actionable solutions in line with industry best practices. Specializing in Network administration, System administration, and Security, I can tackle every aspect of your project's requirements from session handling to Business-logic flaws. With my established proficiency in tools like Burp Suite and OWASP ZAP among others, I can expertly mix various techniques like manual code reviews, automated scanning to conduct the much-needed penetration testing and structured vulnerability assessments your web app needs. Apart from providing you with a comprehensive report aligned with OWASP Top 10 and giving clear remediation guidance, my previous clients highly commend my ability to reproduce and demonstrate high- and medium-severity issues. In addition to using industry-standard reporting formats like PDFs, all deliverables will also be given in an editable format for future use. Let's discuss how I can provide you with the essential security hardening your web application craves.
£135 GBP trong 3 ngày
5,9
5,9

Hi there, I will perform a focused web-application security assessment for your live production site, combining manual code review, automated scanning and targeted penetration testing to find session, auth, input validation and business-logic flaws quickly and safely. - Kick-off call to map attack surface, define safe testing windows and agreed boundaries (no production-impact actions). - Automated scans (Burp Suite / OWASP ZAP) plus custom scripts and manual code review focused on session handling, authentication/authorization, input validation and business-logic flaws. - Reproducible evidence collection and a prioritized PDF + editable report mapping each finding to OWASP Top 10 with clear remediation steps and risk level. - Follow-up walkthrough and remediation guidance; staged retest and rollback/validation plan for each fix. Skills: ✅ Web Security ✅ Burp Suite / OWASP ZAP ✅ Manual code review & threat modelling ✅ Secure deployment / CI-CD integration ✅ Secure session, auth, input validation hardening ✅ Vulnerability validation & staged retest Certificates: ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I can start immediately, deliver the initial report within 3 days, and provide a clear remediation plan plus validation. Do you have a current test/staging environment and CI pipeline, and can you provide temporary read-only access or recent backups for safe testing? Best regards,
£200 GBP trong 3 ngày
5,0
5,0

Hello, I’m a cybersecurity specialist focused on web application security, VAPT, and secure code review, and I can deliver a structured, production-grade security assessment tailored to your live environment. I will approach this using a layered methodology aligned with OWASP standards and the OWASP Top 10 framework, combining: 1. Manual code review on authentication, authorization, session management, business logic. 2. Dynamic testing using tools such as Burp Suite and OWASP ZAP 3. Targeted penetration testing against identified attack surfaces 4. Secure configuration and deployment review What You’ll Receive: 1. Full web-layer security assessment 3. Clear, prioritized vulnerability report (High/Medium/Low) with proof-of-concept evidence 3. Practical remediation guidance with secure coding recommendations 4. PDF + editable report format 5. Follow-up walkthrough session All high and medium issues will be reproducible and documented with impact analysis and mitigation steps and concise, actionable, and executive-ready. If you'd like, I can also provide optional re-testing after fixes to confirm remediation. Regards Kajal Majhi
£300 GBP trong 7 ngày
5,0
5,0

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) would be glad to support you with a structured, production-grade web application security assessment. We specialize in securing live applications that have scaled faster than their internal controls — exactly the situation you described. ? Our Approach We combine: • Manual penetration testing • Targeted automated scanning (Burp Suite, OWASP ZAP, custom tooling) • Logic-level abuse testing • Secure configuration review Focus areas: • Session management & cookie security • Authentication & authorization flaws • Input validation & injection risks • Business logic abuse cases • Deployment & configuration weaknesses ? Deliverables 1. Kick-off scoping call to define boundaries 2. Full web-layer security assessment 3. Detailed report (PDF + editable) including: – Severity ranking (CVSS) – Reproducible PoC evidence – Clear remediation guidance aligned with OWASP Top 10 4. Follow-up walkthrough session with your team All high- and medium-risk findings will be demonstrated and validated. You can review our portfolio, certifications, and client feedback to see similar engagements we’ve delivered successfully. We focus on clarity, reproducibility, and developer-friendly remediation. We can start immediately and align timelines as per your availability.
£240 GBP trong 7 ngày
3,6
3,6

Hello Few questions before proceeding further. Is there a staging or testing environment available, or will testing be performed directly on production? Are there any third-party integrations we should consider in the assessment? I gone through your project description, I have over 9 years of experience in Web development, I will perform a comprehensive web application security assessment focusing on authentication, authorization, session handling, input validation, and business-logic vulnerabilities. Using a combination of manual code review, automated scanning. I will run full vulnerability scans using Burp Suite/ZAP ✪ I will manually review critical flows and reproduce high-risk issues ☎ I will document evidence, severity, and step-by-step fixes. I will advise secure deployment and configuration improvements ☎ I will prepare a clear, actionable report ✪ ✪ Deliverables ✪ A PDF + editable report, demonstration of all medium/high issues, remediation guidance, and a follow-up session to review findings—ensuring your web app is hardened and production-safe. ✪☎ ✪ My aim is to form a long term collaboration ✪ ☎ Let's discuss further and start ☎ Thankyou JATINDER
£60 GBP trong 2 ngày
3,1
3,1

Hello! I’m excited to apply for your web application security engagement. Here’s what we will deliver: ✔️ Full web-layer assessment covering authentication, sessions, authorization, input validation, and business logic flaws. ✔️ Combination of manual code review, penetration testing, and targeted automated analysis. ✔️ Severity-ranked report with clear impact explanation and practical remediation steps aligned with OWASP Top 10. ✔️ Proof-of-concept evidence and a structured retest plan to validate fixes. To ensure both depth and fast turnaround, the assessment will be handled by **two security specialists**, providing parallel analysis and stronger validation of results. Ready to schedule a kickoff call and define scope boundaries. Best regards, Mohamed
£190 GBP trong 7 ngày
2,9
2,9

Please feel free to contact me to discuss this further. I’m highly confident in delivering this project, as I’ve successfully worked on similar systems in my previous company. I approach projects not just as a freelancer, but as a software engineer with a strong focus on system architecture, scalability, and performance — not only functionality or UI. I don’t work solely for payment; I genuinely care about the success of the business behind the project. Contributing to real growth and measurable results is something I truly enjoy as a software developer. If you choose to move forward with me, I will treat this as a business-driven initiative and do my best to ensure it delivers real value. I look forward to your response.
£135 GBP trong 7 ngày
2,1
2,1

Hey, I’ve reviewed your project and understand you’re looking for an application-security specialist to thoroughly assess and harden your production web app. The focus will be on session handling, input validation, authentication, authorization, business-logic flaws, and secure deployment practices, ensuring your app can safely scale. I can perform a detailed security assessment using a mix of manual code review, automated scanning, and penetration testing. You’ll receive a clear, actionable report ranking issues by severity, with evidence and remediation guidance aligned to OWASP Top 10 standards. I’ll also provide a kick-off call to define scope and a follow-up session to walk through results. Let’s connect so I can outline my approach, share examples of previous web app hardening projects, and define timelines for securing your system confidently. Best regards, Muhammad Adil Portfolio: https://www.freelancer.com/u/webmasters486
£100 GBP trong 4 ngày
0,0
0,0

I have just completed a similar project. My last client’s web app security audit revealed and resolved 25+ vulnerabilities, reducing their risk score by 45% within two weeks. You won’t find a specialist more precisely aligned with the technical and operational demands of this project. I understand the importance of comprehensive web-application layer security, including authentication, authorization, and business-logic flaw detection. Expertise: manual code reviews, automated scans, penetration tests, vulnerability assessments, and delivering clear, actionable reports aligned with OWASP Top 10. I’d love to chat about your project! The worst that can happen is you walk away with a free consultation. Regards, Bjork Bronkhorst
£200 GBP trong 7 ngày
0,0
0,0

I've done this exact work before, full web app security assessments covering session handling, auth flaws, input validation, business logic gaps, and deployment misconfigurations. I'll run a combination of manual code review, Burp Suite testing, and automated scanning, document every finding ranked by severity with clear remediation steps, and walk you through it all on a follow-up call. Let's do it.
£120 GBP trong 7 ngày
0,0
0,0

Hi, I’m Ashton Williams, a full-stack software and web developer specializing in secure, scalable web applications. I’ve reviewed your requirements and understand the critical need for a thorough web-application security assessment focusing on session handling, input validation, authentication, and more. Leveraging a combination of manual code review, automated tools like Burp Suite and OWASP ZAP, and penetration testing, I’ll uncover vulnerabilities and provide a clear, prioritized report aligned with OWASP Top 10 standards. With proven experience in hardening live applications, I’m confident in delivering actionable insights and guiding you through remediation. Let’s discuss your project and timelines soon.
£200 GBP trong 14 ngày
0,0
0,0

----------------------- ✅✅✅✅✅ Ready To Support You Fully ✅✅✅✅✅ ----------------------- I understand your web app is live, handling real user data, and needs a structured, professional security assessment focused strictly on the application layer — not just automated scans, but real analysis. My approach: • Kick-off call to define scope, environments, and safe testing boundaries • Manual code review (auth, session handling, access control, input validation) • OWASP Top 10–aligned testing (IDOR, injection, XSS, CSRF, logic flaws) • Dynamic testing using Burp Suite / OWASP ZAP • Business logic abuse testing • Secure configuration & deployment review Deliverables: • Severity-ranked report (High/Medium/Low) • Reproducible evidence + impact explanation • Clear remediation guidance • PDF + editable version • Walkthrough session Goal: actionable fixes, not just findings. Ready to begin with scope clarification and timeline alignment.
£135 GBP trong 7 ngày
0,0
0,0

Hi there, I will provide a thorough security treatment for your production web app immediately to protect your growing user base from potential breaches. Since your platform has scaled faster than your in house safeguards, I will focus on identifying high impact vulnerabilities in your authentication, session handling, and business logic layers. I’ll perform a comprehensive security assessment using a hybrid approach of manual code review and advanced penetration testing with Burp Suite to uncover critical weaknesses. I will evaluate your input validation and authorization flows to ensure they align with OWASP Top 10 best practices and secure deployment standards. This includes a detailed vulnerability report ranking every issue by severity with clear evidence and step by step remediation guidance to harden your production environment. I provide a full walkthrough session after the audit to ensure your team can confidently implement the necessary fixes and secure your sensitive user data. I am ready to secure your platform today. Please share your app’s URL so I can begin the initial surface analysis! Best Regards, Usama F
£199 GBP trong 3 ngày
0,0
0,0

Hello, I’m a CEH-certified security specialist with hands-on experience performing web-application penetration tests aligned with OWASP Top 10 and industry best practices. For your production application, I propose a structured security assessment including: • Kick-off scoping session to define attack surface • Manual penetration testing (authentication, authorization, business logic) • Automated scanning using Burp Suite & OWASP ZAP • API and session handling analysis • Risk-based vulnerability classification • Clear remediation guidance for each finding Deliverables: Professional PDF security report Editable report format Evidence-backed reproduction steps Follow-up walkthrough session I focus strictly on web-layer vulnerabilities and avoid infrastructure disruption, ensuring safe testing on production. Let’s schedule the kick-off call and define scope. Best regards,
£135 GBP trong 3 ngày
0,0
0,0

Hello, and thank you for outlining your security objectives clearly. Web applications often scale faster than their protective controls. The real risk is not the visible flaw — but the unnoticed weakness that quietly exposes user data and business logic. I specialize in structured web-application security assessments focused strictly on the application layer: session management, authentication and authorization controls, input validation, business-logic flaws, and secure deployment practices. My approach combines: • Manual logic review to uncover non-obvious vulnerabilities • Dynamic testing using tools such as Burp Suite and OWASP ZAP • Targeted penetration testing to simulate realistic attack paths • Mapping findings to OWASP Top 10 and industry best practices Deliverables include: Kick-off call to define scope and boundaries Full security assessment Professional report with severity ranking, PoC evidence, impact analysis, and actionable remediation steps Follow-up session to clarify fixes All high- and medium-severity issues will be reproduced and demonstrated. Report delivered in PDF and editable format. If your objective is proactive, measurable security hardening, I’m ready to discuss timelines and begin.
£150 GBP trong 7 ngày
0,0
0,0

I've been pentesting applications from past 5 years and a fast growing live site like yours is always a prime target for session hijacking and business logic flaws. When your user base scales up quickly the in house safeguards simply cannot keep up. I see this all the time and I know exactly how to handle it safely. I will hit your web app with custom automated scanners and then go in deep with aggressive manual testing. I will find the tricky vulnerabilities that automated tools always miss without messing up your live user database. I will document everything clearly in a simple editable Word file so it is very easy for you to read and track. Here is the absolute best part for you. I am a software and computer engineer so I can actually write the secure code and patch these holes for you right away. You do not have to waste time or money looking for another developer to fix what I find. I will test your platform and I will fix it all in one go. Let us get on that kickoff call and lock down your user data today.
£250 GBP trong 7 ngày
0,0
0,0

With over a decade of experience, I am pleased to offer my extensive skill set and insight to help you secure your web application. Safeguarding user data has always been a top priority for me, and I understand that securing a live application with growing traffic can be challenging. However, through my hands-on approach using techniques like manual code review, automated scanning, penetration testing, structured vulnerability assessments, I can provide a comprehensive solution to fortify your system at every level. My proficiencies in multiple programming languages, especially Python, C, andC++ along with experience in AWS architecture are key assets in identifying and mitigating security flaws. I am confident that by leveraging tools like Burp Suite and OWASP ZAP effectively, we can not only uncover any existing weaknesses but also implement secure deployment practices consistent with the recommendations of OWASP Top 10 and industry best practices. In addition to these relevant technical skills, my communication abilities stand out. I guarantee not just an intelligible report in both PDF and editable format but also a follow-up session where we walk through the results together and clarify any necessary fixes.
£100 GBP trong 3 ngày
0,0
0,0

I am a web security tester and bug bounty researcher. I manually test websites the same way a real attacker would, not just using scanners. I will check authentication, access control, API endpoints, XSS, file upload, and configuration issues. You will receive a clear report with proof-of-concept, real impact, and exact fixes your developer can implement. My goal is to show how the website could actually be hacked — and how to properly secure it.
£300 GBP trong 4 ngày
0,0
0,0

Nellore, India
Phương thức thanh toán đã xác thực
Thành viên từ thg 8 25, 2020
₹600-1500 INR
₹600-1500 INR
₹600-1500 INR
₹600-1500 INR
₹600-3000 INR
₹12500-37500 INR
$30-250 USD
£750-1500 GBP
$250-750 AUD
$30-250 CAD
€30-250 EUR
$15-25 USD/ giờ
$30-250 USD
£900-1050 GBP
₹1500-12500 INR
₹1500-12500 INR
₹12000-15000 INR
£900-1050 GBP
$500000-1500000 USD
$30-250 USD
$250-750 USD
$250-750 USD
$10-30 USD
$10-30 USD
₹12500-37500 INR