
Closed
Posted
Paid on delivery
I want a full-scale penetration test carried out against my in-house mobile application suite, which is live on both iOS and Android. The goal is to uncover real-world attack paths, confirm their impact, and give my developers a crystal-clear remediation plan before our next public release. Scope • Assess the compiled apps as they stand in production, plus the traffic they generate with our back-end APIs. • Cover the OWASP Mobile Top 10 and any platform-specific issues unique to iOS or Android (e.g., keychain misuse, insecure storage, WebView hijack, exported components). • Test from the standpoint of an external attacker with no prior credentials; privilege-escalation paths up to an admin account should also be explored. What I need from you 1. A concise testing methodology up front so I can align it with our internal compliance checklist. 2. Periodic progress updates if the engagement stretches beyond a single day. 3. A final report that includes: – Executive summary written in plain English for leadership – Technical findings with evidence (screenshots, code snippets, packet captures) – Risk rating and reproducible PoC steps for every vulnerability – Remediation advice that my development team can act on immediately Acceptance criteria • Every vulnerability is reproducible using the steps you provide. • No production data is altered or destroyed during testing. • The report is delivered in PDF within 48 hours after the live test window closes. Experience with common mobile testing suites—Burp Suite, Frida, OWASP MSTG tools, or similar—will help you move quickly in our environment. If your approach differs, let me know up front so I can provision the right access.
Project ID: 40513324
37 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
37 freelancers are bidding on average ₹23,585 INR for this job

Hi there, I have read your project requirement, and you need a comprehensive penetration test for your live iOS and Android applications, including API traffic analysis and assessment against the OWASP Mobile Top 10. We can perform a thorough security evaluation from an external attacker's perspective, identify privilege escalation paths, and provide a detailed remediation report with reproducible PoCs and actionable recommendations for your development team. We have experience in mobile application security testing, API assessment, and vulnerability analysis while ensuring that no production data is modified or impacted during the engagement. Regular progress updates will be shared throughout the testing process, and the final report will include executive and technical summaries with supporting evidence. A few questions regarding the project: =============================== Will test accounts and staging credentials be provided, or should the assessment begin with completely unauthenticated access? Are there any compliance requirements (OWASP MASVS, PCI-DSS, ISO 27001, etc.) that should be considered during testing? Do you have API documentation available, or should the endpoints be discovered dynamically? Is there a preferred testing window to avoid impacting active users? Best Regards, Srashtasoft Team
₹35,000 INR in 12 days
7.1
7.1

Hello, I can perform a comprehensive security assessment of your iOS and Android applications, covering the OWASP Mobile Top 10, API security, authentication flows, insecure storage, privilege escalation paths, and platform-specific vulnerabilities. My approach includes a documented testing methodology, regular progress updates, and a detailed final report with executive summaries, technical findings, risk ratings, reproducible PoCs, and actionable remediation guidance. I have experience with mobile security testing tools such as Burp Suite, Frida, and OWASP MSTG methodologies, and can ensure all findings are safely validated without impacting production data. Thanks.
₹25,000 INR in 7 days
5.5
5.5

Hello, I am a Cybersecurity Consultant specializing in Mobile Application Penetration Testing for both Android and iOS platforms. I can perform a comprehensive security assessment of your mobile application suite, including API security testing, authentication/authorization review, privilege escalation testing, insecure data storage analysis, and OWASP Mobile Top 10 validation. My methodology combines manual testing and industry-standard tools such as Burp Suite, Frida, MobSF, OWASP MSTG techniques, and API traffic analysis to identify real-world attack paths while ensuring no production data is modified or destroyed. Deliverables include: • Testing methodology aligned with compliance requirements • Regular progress updates throughout the engagement • Executive summary for management • Detailed technical findings with screenshots, packet captures, and PoC steps • Risk-rated vulnerabilities with clear remediation guidance • Final PDF report delivered within 48 hours of test completion I have experience assessing mobile applications, APIs, and cloud-connected environments and can provide reproducible findings that your development team can immediately act upon. Regards Kajal Majhi Cyber security and Digital Forensics Consultant
₹25,000 INR in 7 days
5.0
5.0

✔ I deliver 100% work — 99.9% is not for me. ✔ Workflow Diagram Scope Review ⟶⟶ Threat Modeling ⟶⟶ iOS & Android Assessment ⟶⟶ API & Backend Security Testing ⟶⟶ Privilege Escalation Analysis ⟶⟶ Vulnerability Validation ⟶⟶ Reporting & Remediation Roadmap Key Highlights ✔ Full mobile penetration testing aligned with OWASP Mobile Top 10 and OWASP MSTG standards. ✔ Comprehensive assessment of Android and iOS applications, backend APIs, authentication flows, and session management. ✔ Static and dynamic analysis using Burp Suite, Frida, MobSF, JADX, Objection, and platform-specific testing frameworks. ✔ Testing for insecure storage, certificate pinning bypass, WebView vulnerabilities, hardcoded secrets, exported components, insecure API authorization, and privilege escalation paths. ✔ External attacker simulation with focus on account takeover, authentication bypass, IDOR, business logic flaws, and administrative access exposure. ✔ Safe testing methodology with strict controls to avoid modification or destruction of production data. ✔ Periodic progress updates throughout the engagement with immediate notification of critical findings. ✔ Executive-ready reporting plus detailed technical documentation for development teams. ✔ Reproducible proof-of-concept steps, screenshots, packet captures, risk ratings, and remediation guidance for every finding. Best Regards, Asad Mobile Security Specialist | Penetration Tester | OWASP Mobile Security Expert
₹18,000 INR in 10 days
4.6
4.6

As an experienced Full Stack Web and Mobile App Developer, I have built countless scalable, high-quality, and user-friendly applications in over 5 years of professional work. While I specialize in backend AdventNet like Node.js and Laravel, my frontend skills with React.js can effectively contribute towards your mobile app penetration testing project. I am familiar with the OWASP Mobile Top 10, the keychain misuse, insecure storage, WebView hijack, and other specific issues unique to iOS or Android platforms. Although I'm experienced in using Burp Suite and Frida for mobile testing, I would greatly appreciate if you informed me upfront about any preferred alternatives you have in mind so that I can provision the right access for them. Having a firm commitment to clean, optimized, and maintainable coding practices, I always strive to deliver projects on time while ensuring clear communication throughout each stage. Moreover, my ability to write well-documented code along with my penchant for customer-satisfaction will be an asset when presenting the final report. As a bonus point, my proactiveness allows me to keep you posted with regular updates even if our engagement extends beyond a single day.
₹25,000 INR in 7 days
4.3
4.3

Hello, I can perform a comprehensive penetration test of your Android and iOS applications, including the backend APIs they interact with. My assessment will follow OWASP Mobile Top 10 and API Security best practices while focusing on real-world attack scenarios, privilege escalation paths, authentication weaknesses, insecure storage, WebView issues, exported components, and platform-specific vulnerabilities. Using tools such as Burp Suite, Frida, MobSF, JADX, apktool, and OWASP MSTG methodologies, I will conduct both static and dynamic testing to identify, validate, and document security risks without affecting production data. You will receive: • A concise testing methodology before the engagement begins • Regular progress updates throughout testing • A professional PDF report within 48 hours of completion The final report will include: • Executive summary for leadership • Detailed technical findings with supporting evidence • Risk ratings and impact assessment • Reproducible PoC steps for every vulnerability • Clear remediation guidance for developers My focus is on delivering verified, actionable findings that help your team secure the application before the next release. I am available to discuss scope, access requirements, and timelines. Best regards, Dhruv Patel
₹20,000 INR in 7 days
3.8
3.8

Hello, I'm Karthik, a Cybersecurity Consultant and Mobile Application Architect with 15+ years of experience in security assessments, secure application development, and API testing. I can perform a comprehensive penetration test of your Android and iOS applications, covering OWASP Mobile Top 10, API security, authentication flaws, insecure storage, WebView vulnerabilities, reverse engineering risks, privilege escalation paths, and platform-specific security issues. ✔ OWASP Mobile Top 10 Assessment ✔ Android & iOS Security Testing ✔ API & Backend Security Validation ✔ Burp Suite, Frida & MSTG Methodology ✔ Detailed Proof-of-Concept Findings ✔ Risk Ratings & Remediation Guidance ✔ Executive & Technical Reports ✔ PDF Delivery with Evidence My approach is strictly non-destructive, ensuring no production data is altered while validating real-world attack scenarios. You'll receive clear, reproducible findings with actionable fixes for your development team. I can share a sample reporting structure and testing methodology before engagement and provide progress updates throughout the assessment. Regards, Karthik 15+ Years Experience | Mobile Security | Penetration Testing | API Security
₹50,000 INR in 7 days
3.1
3.1

Hi, I have 8+ years of experience in QA and security testing, including mobile application penetration testing aligned with OWASP Mobile Top 10, API security validation, and backend attack surface analysis. My approach for your mobile app suite: • Start with a clear testing methodology covering iOS/Android attack surfaces, API layer, storage, and privilege escalation paths • Perform black-box + grey-box testing using tools like Burp Suite, Frida, OWASP MSTG, and proxy-based traffic analysis • Validate insecure storage, session handling, WebView risks, and authentication bypass scenarios • Test end-to-end attack flows from unauthenticated user to admin-level access Deliverables: • Executive summary for leadership • Detailed vulnerability report with PoC steps, screenshots, and traffic evidence • Risk ratings with prioritized remediation guidance • Clean, reproducible exploitation paths for every issue found All testing will be conducted carefully to ensure no production data is modified or impacted. Available to start immediately and deliver within your 48-hour window. Profile: https://www.freelancer.com/u/dipak1337 Best Regards, Dipak P.
₹15,500 INR in 7 days
3.0
3.0

With 5+ years of experience in developing and securing high-performance, scalable applications for Android and iOS, I confidently offer you my penetration testing services for your mobile application suite. Throughout my career, I have prioritized security and performance in every project, and the 50+ successful mobile applications I've developed are a testament to this. Moreover, I have vast experience across various real-world client projects and have had to face complex security challenges that demanded action-oriented resolutions. This exposure will ensure that the testing methodology created for your project aligns perfectly with your internal compliance checklist, covers every vulnerability associated with the OWASP Mobile Top 10, and includes any platform-specific issues unique to iOS or Android. Additionally, as a developer in today's technological climate, I understand that mobile security isn't only about identifying vulnerabilities but also recommending actionable solutions promptly. My final report will present each vulnerability in easy-to-understand terms fit for your leadership, coupled with all the necessary technical findings like evidence screenshots, code snippets as well as packet captures. More importantly, it will also provide thorough risk ratings and reproducible proof-of-concept steps to help your team actively work towards remediation.
₹25,000 INR in 7 days
1.9
1.9

As an ex-TCS professional with over 9 years of experience in software development and quality engineering, I've consistently ensured high performance, security and reliability in all my work. My expertise lines up seamlessly with the requirements of your project as I have a solid understanding of mobile app development, testing and I'm well-versed in tools like the Burp Suite, Frida and OSWAP MSTG. Additionally, my experience across diverse areas such as web and mobile application development, SaaS solutions, AI Testing and Finance/ERP systems will allow me to take a multifaceted approach to find not just vulnerabilities but also paths to exploit them akin to an external attacker. Throughout my career, providing insightful, structured reporting has been a cornerstone of my work - this aligns perfectly with your need for concise reports with actionable insights. I consistently maintain reliable communication, which combined with my fast turnaround time will mean that your periodic progress updates during our engagement can be delivered promptly and uninterrupted. Lastly, it's important to note that beyond just finding bugs in the system, I've always prioritized improving overall product quality and user experience.
₹15,000 INR in 7 days
1.1
1.1

Hello, Thank you for sharing the detailed requirements. We can perform a full-scale penetration test of your iOS and Android mobile application suite, including production app builds and mobile-to-backend API traffic. Our goal will be to identify real-world attack paths, validate impact safely, and provide clear remediation guidance before the next public release. We have completed 1000+ security assessment projects, including mobile apps, web apps, APIs, and cloud platforms. Our team has strong knowledge of OWASP Mobile Top 10, OWASP Web Top 10, OWASP API Security, MASVS/MSTG, and iOS/Android-specific security issues. We are also certified with CEH and other cybersecurity certifications. ? Testing Approach: ✅ Static and dynamic analysis of Android and iOS apps ✅ Mobile API traffic testing using Burp Suite and similar tools ✅ Insecure storage, Keychain/Keystore misuse, WebView issues, exported components, SSL/TLS, certificate pinning, reverse engineering, and runtime manipulation checks ✅ Authentication, authorization, IDOR, business logic, and privilege escalation testing ✅ Safe validation without altering or destroying production data ? Deliverables: ? Report through our Report Portal ? Final PDF report within 48 hours ? Executive summary and technical findings with evidence ? Risk rating, reproducible PoC steps, and remediation guidance Looking forward to discussing the next steps. Thanks & Regards, Keyur
₹25,000 INR in 7 days
0.6
0.6

Hi there, I can conduct a rigorous, full-scale penetration test on your iOS and Android mobile applications and backend APIs. With over 3 years of experience in QA, backend workflows, and API architectures, I have strong expertise in tracking system vulnerabilities, analyzing network traffic, and implementing secure coding practices. Technical Methodology & Tools I follow the OWASP Mobile Application Security Verification Standard (MASVS) using industry-standard tools: Static & Dynamic Analysis: Inspecting compiled builds for local storage leaks, insecure Keychains/Keystores, and WebView hijacks using tools like MobSF and Frida. API & Traffic Interception: Utilizing Burp Suite to intercept HTTPS traffic, testing for broken object-level authentication (BOLA), privilege escalation paths, and rate-limiting flaws. Reverse Engineering: Checking for lack of binary protections, obfuscation, and root/jailbreak detection mechanisms. Deliverables Promised (Within 48 Hours Post-Test): Technical Findings Log: Comprehensive breakdown of vulnerabilities mapped to the OWASP Mobile Top 10. Actionable Proof of Concepts (PoCs): Step-by-step reproduction steps with packet captures/screenshots, ensuring zero production data disruption. Remediation Guidance: Clear code/config-level advice for your developers. Ready to align with your compliance checklist and share daily progress updates. Let's secure your app suite! Best regards, Taranveer Singh
₹30,000 INR in 3 days
0.4
0.4

As a seasoned mobile app developer and tester, I am well-versed in the kind of comprehensive penetration testing your mobile application suite requires. My years of experience have given me intimate knowledge of the OWASP Mobile Top 10 as well as platform-specific issues unique to both iOS and Android. Additionally, I possess specialist skills in the use of common mobile testing suites such as Burp Suite, Frida, and OWASP MSTG tools, which would ensure I am able to navigate your unique project requirements easily and efficiently. In line with your needs, my approach emphasizes clear communication and timely delivery of actionable results. From providing you with a concise testing methodology that aligns with your internal compliance checklist to delivering periodic progress updates for more complicated engagements - I have it covered. Drawing from my SEO background, my final report will include every executive-friendly detail like an executive summary in plain English as well as technical findings complete with evidence. And most importantly, it will be delivered within 48 hours after the live test window closes - ensuring minimal disruption to your long term development plans. Let's ensure your next public release is indeed one that's truly secure!
₹12,500 INR in 7 days
0.0
0.0

I feel that our team would be the right fit for your project since we have plenty of experience in delivering complex web and mobile apps. We have the expertise to conduct a full-scale mobile app penetration test covering the OWASP Mobile Top 10, iOS, and Android-specific vulnerabilities, providing a clear remediation plan for your next release. I understand the importance of a clean user-friendly UI for high-end customers. I'd love to chat about your project and how we can assist you. Let's schedule a meeting to discuss your needs and provide you with a free consultation. Regards, Nabeel Ismail
₹16,900 INR in 7 days
0.0
0.0

As a top-rated full-stack developer with vast experience in Android and iOS Development, I am well-equipped to perform the intricate task of 'Mobile App Penetration Testing' for your project. My prowess in utilizing tools such as Burp Suite, Frida, and OWASP MSTG tools aligns perfectly with your stated preference and allows me to make quick progress in your environment. Moreover, my 5+ years of industry experience being exposed to 1000+ completed projects have instilled critical skills that are directly transferable to this task. I have a deep understanding of application vulnerabilities and the tactics employed by attackers which enables me to mimic their methods effectively. Lastly, I believe in open communication and transparency. You can expect periodic progress updates as well as a thorough final report inclusive of an executive summary aimed at addressing your leadership team, technical findings accompanied with substantial evidence plus reproducible PoC steps, risk rating and comprehensive remediation advice for each vulnerability, all within the stipulated timeframe. Let's leverage my ample expertise into making your mobile application suite surpassly secure!
₹25,000 INR in 7 days
0.0
0.0

Hello, I have experience with web and mobile application security testing and follow a structured methodology based on OWASP Mobile Testing Guide (MSTG) and industry-standard penetration testing practices. For this engagement, I would assess both the Android and iOS applications along with the associated API traffic, focusing on authentication, authorization, insecure storage, data exposure, privilege escalation paths, and other OWASP Mobile Top 10 risks. My deliverables will include: • Clear testing methodology before the assessment begins • Regular progress updates during the engagement • Detailed technical findings with supporting evidence • Reproducible proof-of-concept steps for each issue • Risk ratings and practical remediation guidance • Executive summary suitable for management review I understand the importance of maintaining production integrity and ensuring that testing activities do not impact live user data. I would be happy to discuss the application architecture, scope, and testing window before starting. Looking forward to working with you. Regards
₹12,500 INR in 2 days
0.0
0.0

Hello, I reviewed your project requirements and believe we can help deliver a reliable, scalable, and user-friendly solution that aligns with your goals. At IITianCraft, a startup associated with talent from IIT Kharagpur, we work on web development, mobile applications, software solutions, UI/UX design, digital platforms, and business growth systems. Our focus is on: * Clean and modern design * Scalable architecture * Responsive user experience * Performance and security * Long-term maintainability We would be happy to discuss your requirements in more detail and suggest the most suitable approach for development and future scalability. Looking forward to working with you. Thanks, IITianCraft
₹20,000 INR in 7 days
0.0
0.0

Hello, I have experience in security testing and API validation, and I can perform a thorough penetration test of your iOS and Android mobile applications along with the associated backend APIs. My approach includes: * Testing based on the OWASP Mobile Top 10 and platform-specific vulnerabilities. * Assessing authentication, authorization, privilege escalation, insecure storage, WebView issues, exported components, and API security. * Verifying every finding with reproducible proof of concept while ensuring no production data is modified. * Delivering a detailed report with an executive summary, technical evidence, risk ratings, and actionable remediation steps for your development team. I can provide a clear testing methodology before starting and keep you updated throughout the engagement. The final PDF report will be delivered within your required timeline. I look forward to discussing your environment and helping secure your application before the next release. Thank you.
₹25,000 INR in 7 days
0.0
0.0

Hello I have 13 years of experience in mobile app development I will provide you the best mobile app with complete testing please share full scope of your work
₹15,000 INR in 30 days
0.0
0.0

Hello, I am a cybersecurity professional with experience in vulnerability assessment, API security testing, and OWASP-based security reviews. I can perform a structured assessment of your Android and iOS applications, including mobile application security testing, API traffic analysis, authentication and authorization testing, insecure storage checks, and privilege escalation assessment. My approach includes reconnaissance, static and dynamic analysis, traffic interception using Burp Suite, vulnerability validation, and detailed reporting. I will provide a clear executive summary, technical findings with reproducible steps, risk ratings, and actionable remediation recommendations for your development team. I understand the importance of maintaining production integrity and will ensure that no production data is altered or destroyed during testing. I am available to discuss the scope, timelines, and access requirements before starting the engagement. Looking forward to working with you. Regards, Tanvi Bhavsar
₹25,000 INR in 7 days
0.0
0.0

New Delhi, India
Member since Jun 14, 2026
$250-750 USD
$250-750 USD
₹12500-37500 INR
₹600-1500 INR
₹1500-12500 INR
$10-30 USD
$10-30 USD
€250-750 EUR
₹37500-75000 INR
$30-250 USD
€750-1500 EUR
₹12500-37500 INR
$10-30 USD
$30-250 USD
$1500-3000 USD
$15-25 USD / hour
$15-25 USD / hour
₹12500-37500 INR
$30-250 CAD
$50-90 USD / hour