
Closed
Posted
Paid on delivery
Comprehensive Audit (Most Popular) Web Application Penetration Testing A professional web application security audit (black-box analysis) is required. - Identify vulnerabilities from the OWASP Top 10 list (SQLi, XSS, SSRF, etc.). - Check authorization logic, session management, and access rights. - Test API and file upload mechanisms. **Result:** A technical report with a detailed description of each vulnerability, screenshots (PoC), and clear recommendations for remediation. **Timeframe:** [3-5 days]. **Budget:** [from $500 to $2,500]. Option 2: Mobile Application Audit Mobile Application Security Audit (iOS/Android) A mobile application needs to be tested for vulnerabilities and data leaks. - Client-side security analysis (data storage, obfuscation). - Backend security check (API Security). - Search for opportunities to intercept data and bypass security mechanisms. **Result:** A report on identified risks, prioritized (High/Medium/Low) and a step-by-step remediation plan. Ready to provide the build and documentation after signing the application. OSINT and Intelligence (Open Source Intelligence) OSINT Research of the External Attack Surface An audit of the company's external digital presence is required to identify potential attack vectors. **Included in the work:** - Search for forgotten subdomains, open ports, and databases. - Analysis of corporate data leaks and employee accounts. - Identification of vulnerabilities for phishing attacks or social engineering. **Result:** A detailed dossier with an asset map and a list of critical threats that require immediate mitigation. Quick Scan (Small Task) Express Website Security Audit (2-3 days) I need a quick scan of my website for critical vulnerabilities before launch. I'm primarily interested in the most obvious vulnerabilities: exposed configuration files, default passwords, injections, and server configuration errors. **Format:** A brief report with a list of "what to fix right now." Red Teaming (Real Attack Simulation) Infrastructure Attack Simulation (Red Teaming) I need to conduct a controlled simulation of a real attacker's actions. **Goal:** To test not only the security of my systems but also the response time of my team (SOC/admins). **Scenario:** [specify, for example, "penetration of the internal network through phishing"]. Work strictly within the agreed-upon Rules of Engagement. Experience with similar projects is required.
Project ID: 40541012
76 proposals
Remote project
Active 19 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
76 freelancers are bidding on average $1,195 USD for this job

Hi, This looks like a great project and I'd love to help. I have extensive experience delivering high-quality web, mobile, and custom software solutions with a focus on performance, scalability, and clean code. I can start immediately, communicate regularly, and ensure timely delivery with complete support throughout the project. Let's connect to discuss the details and turn your idea into a successful product!
$500 USD in 7 days
9.3
9.3

Hello, I hope you’re doing well. My name is Vishal Nasit, and I represent OM Infowave Software Pvt. Ltd. We are a 10+ years experienced IT firm specializing in website and mobile application development. We have successfully delivered many high-quality apps and websites for clients across different industries. ? Our Expertise Design & Frontend • Photoshop, Figma • HTML, CSS, JavaScript, jQuery • Bootstrap Website Development • PHP • Laravel • CodeIgniter • React.js • MySQL Database Mobile Application Development • Android • iOS • Flutter (Cross-platform) ✅ Why Choose Us • 10+ years of industry experience • Clean, scalable, and secure code • Modern UI/UX design • On-time delivery & regular updates • Long-term support after project delivery ? Our Approach 1. Understand your exact requirements 2. UI/UX design approval 3. Development with regular milestones 4. Testing & quality assurance 5. Final delivery and deployment 6. Ongoing support if required ? Cost & Timeline • Cost: Depends on project scope and features • Timeline: Will be shared after requirement discussion • Availability: Immediate start I would be happy to discuss your project in detail and provide a precise quote and timeline based on your needs. Looking forward to working with you. Best regards, Vishal Nasit OM Infowave Software Pvt. Ltd.
$500 USD in 15 days
8.4
8.4

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
$500 USD in 7 days
7.0
7.0

Hello There!!! ★★★★ (Comprehensive security audit covering OWASP Top 10, API testing, mobile security, and actionable remediation reporting.) ★★★★ I carefully reviewed your project and understand you're looking for a professional security assessment covering web applications, mobile apps, APIs, and external attack surfaces. The goal is to identify vulnerabilities, validate security controls, and deliver a clear, prioritized report with practical remediation guidance. ⚜ OWASP Top 10 penetration testing ⚜ API & authentication security review ⚜ Mobile application security audit ⚜ OSINT & attack surface assessment ⚜ File upload & session testing ⚜ Risk prioritization with PoC ⚜ Detailed remediation documentation I have experience supporting web and mobile security assessments, API testing, and vulnerability validation using industry best practices. I'll follow a structured methodology, document every finding with screenshots and clear recommendations, and ensure testing stays within the agreed scope. My focus is accuraccy, clear reporting, and practical fixes. I'd be glad to discuss your requirements and get started. Warm Regards, Farhin B.
$256 USD in 10 days
6.4
6.4

Hello, Your Web & Mobile Application Security Audit project aligns perfectly with the cybersecurity expertise of Doomshell Software Pvt. Ltd. We specialize in penetration testing, vulnerability assessment, application security, and helping businesses identify and fix security risks. We can help you with: ✔ Web application penetration testing to identify OWASP Top 10 vulnerabilities such as SQL Injection, XSS, CSRF, SSRF, authentication issues, and access control flaws ✔ Mobile application security audits for Android/iOS apps, including data protection, API security, encryption, and vulnerability testing ✔ API and backend security assessment to identify data exposure, authorization issues, and security weaknesses ✔ OSINT and external attack surface analysis to find exposed assets, subdomains, leaks, and potential attack vectors ✔ Red team simulations and controlled security testing to evaluate your system resilience ✔ Providing detailed security reports with vulnerability details, risk levels, proof of concept, and remediation recommendations Our approach: ✔ Analyze your security requirements and application environment ✔ Perform structured security testing using industry best practices ✔ Deliver clear reports with actionable solutions Doomshell Software Pvt. Ltd. is committed to delivering reliable cybersecurity solutions that help organizations protect their applications, data, and digital infrastructure. Regards.
$720 USD in 7 days
6.1
6.1

Hello, I read your project description carefully and understand that you require a comprehensive security assessment covering web applications, mobile applications, APIs, and external attack surface analysis, with detailed reporting and actionable remediation recommendations. We have 9+ years of experience in application security, penetration testing, API security, and secure software architecture. Our team can perform a structured black-box security assessment following OWASP Top 10, testing authentication, authorization, session management, API endpoints, file uploads, and business logic vulnerabilities across your web and mobile applications. For mobile applications, we will assess client-side security, secure data storage, API communication, certificate validation, and potential data leakage. We can also perform OSINT-based external attack surface analysis to identify exposed assets, forgotten subdomains, open services, leaked credentials, and other publicly accessible security risks. You will receive a professional report containing proof-of-concept screenshots, risk prioritization (Critical/High/Medium/Low), detailed remediation guidance, and a summary suitable for both technical and management teams. If required, we can also support remediation verification after fixes are implemented. We can begin immediately and would be happy to discuss the audit scope, Rules of Engagement, and delivery timeline. Thanks Invoke Tech
$2,400 USD in 24 days
5.6
5.6

✋ Hi There!!! ✋ The Goal of the project:- Perform a comprehensive security audit to identify vulnerabilities, assess risks, and provide clear remediation recommendations for your web and mobile applications. I carefully read the complete project description and understand you need an experienced security professional to perform penetration testing, assess OWASP Top 10 vulnerabilities, review API and mobile security, and deliver detailed reports with prioritized remediation guidance. With 9+ years experience as a full stack developer, I can provide structured security assessments with accurate findings and practical solutions. 1. Perform web and mobile security testing including OWASP Top 10 and API assessments. 2. Analyze authentication, session management, file uploads, and access controls. 3. Deliver a detailed report with PoC screenshots, risk levels, and remediation steps. I also provide UI review, database management, testing, full source code delivery at project completion where applicable, and complete technical documentation. I have completed similar penetration testing and security audit projects for web and mobile applications. Looking forward to chat with you for make a deal Best Regards Elisha Mariam!
$251 USD in 7 days
5.0
5.0

Hi, there. I have carefully reviewed the requirements for Web & Mobile Application Security Audit. Based on your goals, you are looking for a mobile experience that is not just functional, but seamless and responsive for your users. My team and I specialize in mobile app engineering with a focus on high-performance architecture. We have a proven track record of helping businesses in Vietnam build mobile solutions that scale effectively across both iOS and Android. Whether we are leveraging Web Security, Android for a native build or a cross-platform solution, our focus is on ensuring the interface is intuitive and the backend data handling is secure. We treat every app we build as a long-term asset. We avoid common pitfalls in mobile development such as memory leaks or poor UI responsiveness, ensuring your users have a smooth experience from their very first interaction. To help me provide a precise timeline for your development, I have one quick question: Are you aiming to launch on both platforms simultaneously, or are you prioritizing one (iOS or Android) for your initial market validation? Knowing this helps me determine the most efficient architectural path for your project. I am available for a discovery call to discuss your mobile roadmap whenever you are ready. Best regards Kausar and the Team
$350 USD in 3 days
5.3
5.3

As an experienced web and mobile application security expert, I’ve conducted numerous comprehensive audits similar to your project requirements. I am well-versed in identifying vulnerabilities from the OWASP Top 10 list, testing API and file upload mechanisms, as well as checking authorization logic, session management, and access rights. Moreover, my skill set extends to conducting mobile application audits wherein I proficiently investigate client-side security issues like data storage and obfuscation while also scrutinizing the backend for vulnerabilities. My reporting method involves prioritizing risks into high/medium/low with a clear step-by-step remediation plan. In addition to these services, my extensive experience in Network and Cybersecurity make me an apt candidate for your Red Teaming requirement. I have successfully conducted controlled simulations of real attacker's actions, proving valuable for testing system security and response time of the SOC team or administrators. With me on board, not only will you receive precise analysis but my work will also comply strictly with agreed-upon Rules of Engagement. Choose me if you want effective solutions delivered within stipulated timeframe and budget. Let's safeguard your applications together!
$500 USD in 7 days
4.8
4.8

I specialize in conducting professional web and mobile application security audits, focusing on identifying vulnerabilities and providing clear remediation recommendations. With extensive experience in delivering detailed technical reports for clients, I guarantee a thorough analysis of your applications' security. I have successfully completed similar projects outside this platform, ensuring clean execution and reliable results. How can I assist you with securing your web and mobile applications effectively? Pieter
$1,450 USD in 7 days
4.4
4.4

As an accomplished freelancer with over a decade of experience in mobile and web application development, specializing in Android and the MERN stack, my team at Trydigital Solution boasts the needed security expertise to undertake this comprehensive security audit. We have an established reputation for producing high-quality results, backed up by our extensive knowledge and use of industry-leading best practices such as OWASP Top 10 vulnerability testing. Our audits include rigorous penetration testing, risk analysis and documented proof-of-concept where necessary, all crucial components of this project to expose and address vulnerabilities. Beyond technical skills, I also offer a depth of knowledge in API security and backend system administration which will be highly valuable during this audit. As a bonus in line with the OSINT portion of this project, I can leverage my experiences in researching digital presence plus corporate data leak and employee account analysis to further safeguard your assets from phishing attacks and social engineering exploitations. I guarantee a diligently handled project delivered within your desired timeframe and budget range while ensuring your peace of mind about all vulnerabilities being identified. Let's foster powerful digital products on time together, within budget, and built to scale! Thanks, Ekta
$500 USD in 7 days
5.2
5.2

Hi, I hope - you are doing good, you're building is really exciting. I'm Abbas, I'm inerested in your project. I read carefully your project details, I understood requirements but I have some questions, so can we discuss about project in brief? and we are specializing in website design/redesign, mobile apps (Android/iOS), and AI solutions for startups, and we are doing help of customers exiting business growth. Are you currently looking to build or improve your product? I'd love to hear what you're working on. Portfolio: https://www.freelancer.in/u/letsgood Best, Abbas
$1,000 USD in 18 days
3.5
3.5

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can support all of the security assessments listed. Our Expertise ✅ Web Application Penetration Testing * OWASP Top 10, business logic, API security, authentication, session management, file upload, SSRF, SQLi, XSS, CSRF, IDOR * Manual + automated testing with Burp Suite, OWASP ZAP, SQLMap, Nuclei, Nmap ✅ Mobile Application Security (iOS & Android) * OWASP MASVS / Mobile Top 10 * Static & Dynamic Analysis, API security, insecure storage, certificate pinning, runtime testing * Tools: MobSF, Frida, Burp Suite, JADX ✅ OSINT & External Attack Surface Assessment * Asset discovery, subdomain enumeration, exposed services, leaked credentials, DNS and email security review * Risk analysis for phishing and social engineering exposure ✅ Red Team Assessments * Controlled adversary simulations aligned with agreed Rules of Engagement * Initial access, privilege escalation, lateral movement, persistence, and detection validation Deliverables • Executive Summary • Detailed technical report with CVSS severity, PoCs, screenshots, and remediation guidance • Risk-prioritized action plan • Optional remediation retest and validation We deliver manual, evidence-based security assessments with actionable findings and can begin immediately after scope confirmation and NDA execution.
$2,000 USD in 5 days
3.6
3.6

Hiii, ✋ ___ The audit will include testing for OWASP Top 10 vulnerabilities, authentication & authorization issues, API security, session management, file upload validation, & common server misconfigurations. For mobile apps, I can assess client-side security, backend/API exposure, & potential data leakage. You'll receive a detailed report with risk ratings High/Medium/Low, proof-of-concept evidence, screenshots where applicable. Available to start & deliver the best work with 8 yrs of proficiency. -- Regards, Ravi s.
$402 USD in 12 days
3.2
3.2

Hello! As per your project post, you are looking to perform a professional security assessment covering web applications, mobile applications, OSINT, or infrastructure depending on the selected engagement. The goal is to identify real-world vulnerabilities, validate security controls, and deliver actionable remediation guidance through a structured, evidence-based audit. My focus will be on conducting a comprehensive assessment using industry-standard methodologies including OWASP Top 10 testing, API security validation, authentication and authorization review, session management analysis, file upload testing, mobile client and backend assessment, OSINT reconnaissance, or controlled Red Team exercises within the agreed Rules of Engagement. Every verified finding will include PoC screenshots, risk prioritization, technical analysis, and practical remediation recommendations. I specialize in penetration testing, application security, API security, infrastructure assessments, OWASP testing, OSINT, and security reporting. My approach focuses on accurate validation, minimal business disruption, reproducible findings, and clear documentation that enables your development team to remediate issues efficiently. Let’s connect to define the assessment scope and deliver a thorough security audit that provides measurable security improvements. Best regards, Prateek
$399 USD in 7 days
2.7
2.7

Hi, I have 8+ years of experience in cybersecurity, application security, and QA, specializing in Web, API, and Mobile security testing. I have hands-on experience with OWASP Top 10, authentication/authorization testing, API security, session management, data leakage analysis, and vulnerability validation. Achievements: ◆ CVE-Credited Security Researcher (CVE-2019-13655, CVE-2020-8452, CVE-2022-26070) ◆ 50+ Security Hall of Fame recognitions including Google, Microsoft & NCIIPC ◆ Google Bug Hunter & featured bug bounty researcher I provide clear security reports with severity ratings, PoC evidence, impact analysis, and actionable remediation guidance. Ready to start and deliver a professional security assessment within your timeline. Best Regards, Dipak P.
$600 USD in 7 days
2.7
2.7

Hello BosS Hi, I have experience working with Linux servers, infrastructure security, VoIP systems, firewall hardening, and vulnerability assessment. I’ve handled security troubleshooting and system audits before. Could you share which environment needs to be audited first — web app, infrastructure, or API?
$270 USD in 2 days
1.7
1.7

9+ years in offensive security (OSCP, OSWP, eJPT, EHMWX), including Red Team leadership across Web, Infrastructure, Mobile, API, Cloud, IoT and RF. For $250, delivered in 10 business days, I'll run three engagements together: Web Application Audit, Mobile Application Audit, and OSINT / External Attack Surface Assessment. Plan: Days 1-2 OSINT (subdomains, exposed assets, leaked credentials, phishing exposure) -> Days 3-7 Web Audit (OWASP Top 10, authorization logic, session management, API and file upload testing) -> Days 8-10 Mobile Audit (client-side storage/obfuscation, backend API, interception/MITM testing). Deliverable: one consolidated report with PoC screenshots, severity ratings (High/Medium/Low) and actionable remediation steps. Certifications and experience are hands-on, not theoretical - manual testing catches the logic/authorization flaws automated scanners miss. Quick scoping: user roles + auth type for the web app, iOS/Android for mobile, and whether OSINT should include employee exposure or stay technical-only. Signed scope and authorization required before testing starts. Can begin within 24-48 hours of signing.
$250 USD in 10 days
1.6
1.6

As an experienced development team, we at Digii Vibes have more to offer than just the ability to code and build - we understand the critical importance of secure application development and, importantly, ensuring that each build is fully protected against outside threats. We understand that security doesn't just happen; it has to be purposefully designed, coded for and tested relentlessly. Our comprehensive skills in mobile, web and application security audits make us suited perfectly-suited for this project. Our extensive knowledge of OWASP top 10 list allows us not only to identify vulnerabilities like SQLi, XSS, SSRF and fix them but also check other vital aspects of security such as authorization logic, session management, access rights, api/file upload mechanisms and backend security check. In addition, we have a solid understanding of Red Teaming methods such as penetration testing, simulating attack scenarios like phishing that can primarily help test your system's security as well as response time. Moreover, we'll provide a clear and detailed technical report with proof of concept (POCs) screenshots, risk rating as well as actionable roadmap for remediation strategy. Lastly, we take pride in the long-term relationship we create with our clients. Therefore we don’t leave you once the project is completed. We’ll support you till you grow your product offering continued services.
$250 USD in 7 days
0.8
0.8

Hello, I have read your requirements carefully and can perform a comprehensive security assessment of your web and mobile applications, covering OWASP Top 10 vulnerabilities, API security, authentication, session management, access control, file upload testing, and overall security posture. I have experience with penetration testing, web security assessments, API testing, mobile application security, OSINT, and vulnerability analysis. I'll provide a detailed report with proof-of-concept screenshots, risk ratings (High/Medium/Low), technical findings, and step-by-step remediation recommendations. If required, I can also perform external attack surface analysis and work within clearly defined Rules of Engagement for controlled security testing. You'll receive a well-structured report, complete documentation, and recommendations to strengthen your application's security before production. Best regards, Prachi
$500 USD in 10 days
0.4
0.4

Nha Trang, Vietnam
Member since Mar 9, 2025
$250-750 USD
$250-750 USD
₹100-400 INR / hour
₹12500-37500 INR
$3000-5000 USD
$8-15 USD / hour
$30-250 USD
₹600-1500 INR
₹600-1000 INR
€1500-3000 EUR
₹100-400 INR / hour
$3000-5000 USD
₹5000-200000 INR
₹12500-37500 INR
$250-750 USD
$250-750 USD
min $50 USD / hour
$10-30 USD
$30-250 USD
$15-25 USD / hour