
Closed
Posted
Paid on delivery
I have a web-based project running only on my own machine and I want proof of how breakable it actually is. Your task is to ethically hack this localhost build, show me exactly where it fails, and explain how to fix each issue. The engagement is strictly a security audit: I own the code and the environment, so there are no legal grey areas. The spotlight is on the OWASP Top Ten for AI-driven applications—things like insecure model interfaces, data poisoning, privilege escalation through prompt injection, and any other risks unique to agents that call LLMs behind the scenes. Traditional web flaws (SQLi, XSS, broken auth, etc.) still matter, but only insofar as they intersect with the AI components. Because I need results ASAP, we will work in two short milestones: 1. Exploitation walkthrough 2. Remediation roadmap Please provide: • A reproducible exploit or proof-of-concept for every vulnerability you uncover (screenshots or short Loom clips are fine). • A concise report summarising impact, CVSS-style severity, and concrete fixes. If you leverage Burp, OWASP ZAP, Metasploit, or custom Python tooling, mention that in your bid—whatever gets to the truth fastest is perfect. I can spin up the environment for you over VPN or share a Docker image, whichever is quicker for you. I’m ready to start as soon as you are; the sooner the findings land, the better.
Project ID: 40647215
21 proposals
Remote project
Active 2 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
21 freelancers are bidding on average ₹3,565 INR for this job

Hi, I’m a CEH/CHFI-certified Cyber Security & Digital Forensics professional with 9+ years of experience in VAPT, web/API security, mobile security, and Digital Forensics investigation. I can perform a focused AI application security audit of your localhost environment, prioritizing OWASP risks for AI-driven applications prompt injection, insecure model interfaces, excessive agent privileges, data leakage/poisoning, improper authorization, and LLM-to-tool/API abuse alongside relevant SQLi, XSS, authentication and access-control issues. I’ll use Burp Suite, OWASP ZAP, custom Python tooling, and manual testing as appropriate to validate findings rather than relying solely on automated scans. Deliverables: 1. Reproducible PoC evidence for each confirmed vulnerability 2. Impact and CVSS-style severity assessment 3. Screenshots/video evidence where useful 4. Clear remediation guidance and prioritized roadmap I can work through VPN-accessible environment and start immediately. My approach will be evidence-driven, controlled, and focused on demonstrating realistic impact without unnecessary disruption. Regards Kajal Majhi
₹35,000 INR in 7 days
5.3
5.3

Hi, I can security-test your localhost AI application against OWASP risks, including prompt injection, insecure AI interfaces, privilege issues, and relevant web vulnerabilities. I’ll provide reproducible PoCs, clear severity ratings, screenshots where useful, and practical fixes using tools like Burp/ZAP and custom testing. let’s discuss in chat as I have some queries to ask regarding the project to proceed further. ⭐ 5.0/5 from a recent client: "Abdul S delivered the work exactly as per my expectations, within the agreed time and budget."
₹1,050 INR in 1 day
2.6
2.6

Hello there, hope you are having a fantastic day so far! Penetration testing is my main line of work, 25 plus engagements including Fortune 500 clients, and a localhost build you own outright is clean scoping. Straight answer on the AI portion, because you should know what you are buying: I have not run a formal LLM red team engagement under a published methodology. What I do have is years of conventional web and network pentesting, graduate level teaching in cybersecurity, and hands-on experience building LLM applications myself in n8n, Python and API integrations. That last part matters here: I know where these systems are wired loosely, because I have wired them. Unvalidated tool calls, prompt context that implicitly trusts retrieved data, model output flowing into privileged actions with no gate in between, secrets reachable from the agent runtime. Milestone 1, exploitation walkthrough. Burp Suite and OWASP ZAP across the conventional surface, then manual work on the model interfaces: direct and indirect prompt injection (including through any data the agent ingests), tool and function call abuse, context leakage, and privilege escalation through the agent's permissions. Every finding ships with a reproducible proof of concept and screenshots or a short clip. Milestone 2, remediation roadmap. Impact, CVSS style severity, concrete fixes. Docker image is faster than VPN on my side. Ready when you are. VR, Vicente Muñoz
₹2,800 INR in 4 days
1.4
1.4

Hi, I’m a software developer with experience in Python, web applications, APIs, authentication, AI/LLM integrations, and application security testing. I can perform a structured security assessment of your isolated localhost/Docker environment, focusing primarily on AI-specific attack surfaces while also checking traditional vulnerabilities that can affect the LLM/agent workflow. I’ll assess areas such as prompt injection, insecure model/tool interfaces, excessive agent permissions, sensitive-data exposure, improper output handling, API/auth weaknesses, and privilege boundaries. I can use Burp Suite/OWASP ZAP alongside targeted Python testing and manual verification. Milestone 1 – Exploitation • Map AI and web attack surfaces • Validate vulnerabilities with reproducible PoCs • Capture evidence and reproduction steps • Assign severity/impact Milestone 2 – Remediation • Root-cause analysis • Concrete code/configuration fixes • Prioritized remediation roadmap • Retesting guidance The final report will clearly document each confirmed finding, reproduction steps, impact, CVSS-style severity, recommended fix, and supporting evidence. I can work with a Docker image or controlled VPN-accessible test environment and can start immediately.
₹600 INR in 4 days
0.7
0.7

Hi, I can perform a focused security audit of your localhost application and provide reproducible findings with clear remediation steps. Since you own the environment and code, I can work directly against the provided Docker image or VPN-accessible setup and keep the testing strictly within the agreed scope. I’ll prioritise the AI-specific risks you highlighted, including prompt injection, insecure LLM/model interfaces, excessive agent privileges, data poisoning, sensitive data exposure, and unsafe tool/function execution, while also checking relevant traditional web vulnerabilities such as authentication, authorisation, SQL injection, XSS and API security. My approach will include: * OWASP-focused AI application security testing * Prompt injection and privilege-escalation testing * LLM/tool and agent interaction analysis * Authentication and authorisation testing * API, input validation and data exposure checks * Reproducible PoCs for confirmed vulnerabilities * Burp Suite / OWASP ZAP and custom Python tooling where appropriate * Severity and impact assessment * Screenshots/evidence for each confirmed issue * Concise remediation roadmap with practical fixes I’ll structure the work around your two milestones: exploitation walkthrough followed by remediation guidance. I can start quickly and focus on producing actionable results rather than unnecessary scanning noise. Best regards, Aryan
₹650 INR in 2 days
0.0
0.0

I can start from your Docker image today and keep all actions inside the authorized target. I will map the AI attack surface; test prompt-injection and tool-permission boundaries, model/API validation, secrets/logging, and relevant auth/session controls; and preserve exact requests and responses. Deliverables will be reproducible Python/ZAP evidence, screenshots, impact, CVSS-style severity and fixes, followed by a prioritized remediation roadmap. Please provide Docker, a test account and allowed model/API budget.
₹1,500 INR in 2 days
0.0
0.0

Hi, Your project is exactly the kind of security engagement I specialize in: authorized exploitation followed by practical remediation. I’ll focus on finding real, reproducible attack paths rather than delivering a generic checklist. I’ll prioritize AI/LLM risks such as: Prompt & indirect prompt injection Excessive agent permissions and unsafe tool use Privilege escalation Insecure model/API interfaces Sensitive data leakage through prompts, memory, or tools Data/model poisoning AI-specific business-logic flaws Authorization, authentication, API and web flaws affecting AI workflows Milestone 1 — Exploitation I’ll map the attack surface and validate confirmed vulnerabilities using Burp Suite, OWASP ZAP, custom Python tooling, and manual testing where appropriate. For each finding, you’ll receive a reproducible PoC, attack steps, evidence/screenshots, impact, severity, prerequisites, and realistic attacker outcomes. Milestone 2 — Remediation I’ll provide concrete fixes covering agent permissions, authorization boundaries, prompt/context isolation, validation, secrets handling, logging, guardrails, and regression testing. I’m comfortable working through your Docker image or VPN environment and can start immediately. My goal is simple: break the application safely, demonstrate exactly how it breaks, and give you a clear roadmap to make those attacks fail.
₹5,000 INR in 2 days
0.0
0.0

This project immediately caught my attention because it is exactly the type of work I do best. The focus on the OWASP Top Ten for AI-driven applications, particularly the risks around insecure model interfaces and privilege escalation, aligns perfectly with my expertise in security auditing. While I am new to freelancer, I have tons of experience and have done other projects off site, utilizing tools like Burp Suite, OWASP ZAP, and custom Python scripts to identify vulnerabilities and provide clear remediation roadmaps. If this sounds like what you're looking for I'd love to hear more about your project. Regards, Warrick Van Eeden
₹700 INR in 7 days
0.0
0.0

I'll conduct a focused two-phase security audit of your localhost AI application, targeting OWASP Top Ten vulnerabilities with emphasis on LLM-specific attack vectors like prompt injection, insecure model interfaces, and data poisoning risks. Phase 1 delivers reproducible exploits with PoC scripts (Python-based fuzzing and Burp automation) plus visual evidence of each vulnerability; Phase 2 provides a detailed remediation roadmap with CVSS ratings and concrete code fixes. I'll use a combination of OWASP ZAP, custom Python tooling, and manual testing to surface both traditional web flaws (SQLi, XSS, auth bypass) and AI-layer weaknesses. You'll receive a concise executive summary, technical deep-dives for each finding, and prioritized fix recommendations. VPN or Docker image access works perfectly for my workflow, and I can start immediately to meet your timeline.
₹606 INR in 3 days
0.0
0.0

Hello, I’m Bharghav, and I bring 10 years of experience in matching job skills, particularly in Python. This project aligns perfectly with my expertise where I can offer valuable insights into security auditing for your web-based application. I understand your requirement for a thorough and ethical hacking assessment of your localhost setup, focusing on OWASP Top Ten vulnerabilities specifically in AI-driven applications. I will provide a detailed exploitation walkthrough and a remediation roadmap, ensuring you receive reproducible proofs for each vulnerability alongside a concise report summarizing the impacts and fixes.
₹1,050 INR in 3 days
0.0
0.0

As an AI system developer with a strong focus on security, I am the perfect fit for your Localhost Vulnerability Audit Demo project. My expertise lies in Python, FastAPI, PostgreSQL, Celery, Docker, and many more - all of which are wholly relevant to this task. I have a proven track record of building and securing production-grade AI systems such as LLM for RAG with citation verification, agent orchestration, etc., which exhibit impeccable performance under strict scrutiny. My proficiency extends to leveraging renowned tools like Burp, OWASP ZAP, Metasploit, as well as custom Python tooling which ensures I can identify and exploit even the most discreet vulnerability in your project promptly. And not only do I excel at exposing potential risks, but I also provide a comprehensive remediation roadmap to rectify each finding. This way you not only gain insights into the weak points of your localhost build but also secure it effectively to mitigate future threats. To attest to my competence further, you can visit my website where you can explore an open-source MIT framework called 'open-deal-kit' and take a glimpse into my code quality. It's evident that I don't just focus on developing AI systems; rather my approach entails ensuring they are robust and impregnable from any conceivable breach. With that said, I guarantee actionable findings and a quick turnaround for your project. Let's get started so you can sleep soundly knowing your localhost is unhackable!
₹1,500 INR in 7 days
0.0
0.0

Hi, I can perform a focused security assessment of your localhost AI-enabled web application in the authorized environment you provide. I’ll approach the engagement in two phases: first, identifying and reproducing exploitable weaknesses; second, documenting practical remediation steps. The assessment can cover AI-specific attack surfaces such as prompt injection, insecure model/tool interfaces, excessive agent permissions, sensitive-data exposure, unsafe output handling, and authorization boundaries, together with relevant traditional web vulnerabilities such as broken authentication, XSS and injection issues where they affect the AI workflow. I can work against a Docker image or through your VPN-accessible test environment and use tools such as Burp Suite, OWASP ZAP and Python-based testing where appropriate. For each confirmed issue I’ll provide: • reproducible proof of concept • impact and severity assessment • affected component/workflow • concrete remediation guidance • retesting notes where applicable I can start immediately. If possible, please share the application architecture/framework and whether the agent has access to external tools, databases, files, or privileged APIs.
₹1,050 INR in 2 days
0.0
0.0

Olá! Sou um profissional em início de carreira em segurança ofensiva, atualmente ativo em programas reais de bug bounty (Bugcrowd). Meu ambiente de trabalho é 100% baseado em Android/Termux, o que trouxe uma vantagem pouco comum: domínio profundo de linha de comando Linux, automação em Python e reconhecimento manual, sem depender de interfaces gráficas pesadas. Sendo transparente: não tenho, hoje, um ambiente desktop para rodar Burp Suite, ZAP ou Metasploit da forma completa que um projeto de auditoria contra os OWASP LLM Top 10 normalmente exige. Por isso, antes de aceitar o escopo completo, gostaria de alinhar com você: Se aceita testes conduzidos via ferramentas de linha de comando/Python customizadas (nmap, sqlmap, scripts próprios de fuzzing/prompt injection) em vez do trio Burp/ZAP/Metasploit; Se pode disponibilizar acesso remoto (VPN) a uma máquina com essas ferramentas já instaladas — nesse caso consigo operar normalmente; Um escopo reduzido inicial (ex: só os riscos de prompt injection e exposição de dados sensíveis via LLM) como piloto de confiança antes do relatório completo em 7 dias. Prefiro alinhar isso agora a prometer um Burp/ZAP completo e não entregar. Se topar essa conversa, posso começar imediatamente.
₹1,050 INR in 7 days
0.0
0.0

Hello, I’m a Cybersecurity Analyst and VAPT Professional with 3+ years of experience in Web Application, API, and Network Security. Your AI-driven application security audit is a strong match for my expertise. I can perform an authorized security assessment focusing on AI/LLM-specific risks as well as traditional vulnerabilities affecting AI components. **I will test for:** • Prompt & Indirect Prompt Injection • Excessive Agency and unsafe agent actions • Privilege escalation & authorization bypass • Sensitive information disclosure • Insecure model/API interfaces • Insecure tool/function calling • Data poisoning & untrusted data handling • Authentication, SQLi, XSS, SSRF and API issues where relevant **Tools:** Burp Suite Professional, OWASP ZAP, Nmap, Nuclei, ffuf and custom Python tooling, combined with manual testing. For every confirmed vulnerability, I will provide reproducible PoCs, exploitation steps, evidence/screenshots, impact, CVSS-style severity, root cause and concrete remediation recommendations. I can follow your two milestones: 1. Exploitation Walkthrough 2. Remediation Roadmap I can work through Docker or VPN access and start immediately. All testing will remain strictly within the authorized scope. Best regards, Cybersecurity Analyst | VAPT Specialist
₹1,050 INR in 3 days
0.0
0.0

Hi , I am the CTO at Defnyx Infosec and an active security researcher who has responsibly disclosed critical vulnerabilities to organizations like NASA, BMW, and Uber. My core focus is actively breaking into web applications, APIs, and cloud infrastructure before malicious actors do. Why I am the best fit for your project: Real-World Offensive Expertise: Specializing in web, API, and network penetration testing (SQLi, XSS, IDOR, SSRF, auth bypasses, and cloud misconfigurations). Actionable Security Reporting: You won't just get automated scanner dumps. I provide zero-false-positive, manually verified findings with clear, step-by-step remediation guidance. Industry & Compliance Standards: Certified ISO/IEC 27001 Lead Auditor and SSCP, ensuring tests align with global security frameworks. Let’s connect to discuss your scope so we can secure your assets efficiently.
₹1,500 INR in 7 days
0.0
0.0

Hi, I’m interested in helping you assess the security of your local web application in the authorized testing environment you described. My background includes 7+ years of web development with PHP, WordPress, JavaScript, SQL, REST APIs, and custom web applications, along with practical experience investigating web application security issues and debugging application-level vulnerabilities. For this project, I can approach the assessment systematically: Map the application's attack surface and exposed functionality Test common OWASP web application vulnerabilities Review authentication, authorization, input validation and API behavior Investigate injection, access-control and configuration issues Use Python/custom tooling where appropriate for repeatable testing Document reproducible proof-of-concepts for confirmed findings Provide severity/impact information and practical remediation steps Prepare a concise remediation roadmap prioritized by risk I understand that the deliverable needs to be reproducible rather than simply a list of theoretical vulnerabilities. I will therefore document the conditions required to reproduce each confirmed issue and clearly distinguish confirmed findings from potential risks. I’m available to start immediately and can work through the two requested milestones: exploitation assessment followed by remediation recommendations. Regards, Tyagraj
₹1,050 INR in 7 days
0.0
0.0

Hi, I'm Fernando from FCyberSecurity LLC. We're newer to Freelancer, so I'm pricing this one competitively while still delivering full scope - no shortcuts. For this engagement I'll cover both traditional and AI-specific attack surface as scoped: - Traditional: SQLi, XSS, broken auth, and other standard OWASP Top 10 flaws, tested with Burp Suite/OWASP ZAP plus custom Python scripts where needed. - AI-specific: insecure model/LLM interfaces, prompt injection paths that lead to privilege escalation, data poisoning vectors, and other risks unique to agents calling LLMs - this is the part most generalist pentesters skip, and it's the part you specifically asked for. Milestone 1: exploitation walkthrough with reproducible PoCs (screenshots/short clips) for every finding. Milestone 2: remediation roadmap with CVSS-style severity ratings and concrete fixes. Docker image works fine for me - happy to start as soon as you share it. Note: this rate is a limited-time offer for our early Freelancer clients, valid until tomorrow at noon your time - happy to lock it in if you move forward before then.
₹600 INR in 7 days
0.0
0.0

Hi, Rather than simply running scanners, I use my own AI-assisted security testing system with Human-in-the-Loop validation and Adaptive Pentesting. The adaptive approach continuously adjusts the testing strategy based on the target’s behavior, discovered attack surface, responses, and previous findings—allowing the assessment to go deeper into promising attack paths instead of following a fixed checklist only. The system helps with reconnaissance, attack-surface analysis, test coverage, attack-path discovery, and finding correlation. I then manually review and validate the results to confirm real impact and eliminate false positives. I can assess web applications, APIs, SaaS platforms, infrastructure, and other authorized environments, adapting the methodology to the specific target and scope. The deliverable will be a concise report focused on validated findings, evidence, impact, severity, and prioritized remediation rather than a long list of automated scanner results. I can start immediately.
₹600 INR in 1 day
0.0
0.0

Hello, I can perform an authorized and reproducible security audit against your Docker or VPN-accessible localhost environment, focused on OWASP LLM/AI risks plus authentication, injection, and data-flow issues that intersect with the AI layer. I will use Burp/ZAP and targeted Python tests within the agreed scope, then deliver verified findings with proof of concept, impact and severity, evidence, remediation steps, and a short retest. Please share the stack and preferred access method after award.
₹3,000 INR in 3 days
0.0
0.0

Pune, India
Member since Aug 14, 2026
$25-50 USD / hour
₹37500-75000 INR
₹750-1250 INR / hour
₹75000-150000 INR
$250-750 CAD
$250-750 USD
$3000-5000 USD
$25-50 USD / hour
$30-60 SGD
₹600-900 INR
₹1500-12500 INR
$10-30 USD
$3000-5000 USD
$8-15 USD / hour
₹37500-75000 INR
$30-250 USD
$10-30 USD
₹600-1500 INR
£500-1000 GBP
$2-8 USD / hour