arrow_back العودة إلى الأعمال الحرة
F

Comprehensive Security Check for my Platform

Freelancer

مشاركة:
placeIN home_workعن بُعد assignmentبعقد publicوظيفة مجمّعة · IN

eventنُشرت في 04 سبتمبر 2026 · verifiedتحققنا في 04 سبتمبر 2026 من أنها ما زالت متاحة

₹ 600 – ₹ 1.500 / لكل مشروع

عن الوظيفة

Security Audit and Penetration Testing for Web and Mobile Application Project Overview I am looking for an experienced security auditor and penetration tester to perform a comprehensive security audit of a web application and mobile application. The application handles sensitive user and platform data through a backend database. The main objective of this project is to identify security vulnerabilities and, most importantly, verify that unauthorized users cannot access data or functionality that they are not permitted to access. The primary focus is on backend authorization, API security, database access control, authentication, privilege escalation, and protection against unauthorized data access. Main Security Requirement I need to verify that a normal user cannot access another user’s private or restricted information by manipulating API requests, IDs, parameters, requests, or other application components. For example: * User A must not be able to access User B’s private information. * User A must not be able to access User B’s products or records. * User A must not be able to access User B’s chats or messages. * User A must not be able to access User B’s rental or transaction information. * User A must not be able to access restricted KYC or sensitive information. * User A must not be able to modify or delete User B’s information. * A normal user must not be able to access administrator functionality. * A normal user must not be able to change their role or privileges. * Unauthenticated users must not be able to access protected APIs. The security controls must be enforced on the backend/server side and should not rely only on frontend restrictions. Scope of Testing 1. Web Application Security Test the complete web application, including: * Authentication and login * Registration * User profiles * Product listing and management * Product browsing * Rental functionality * Transactions and payments * Chat and messaging * KYC functionality * Notifications * Search * User-specific data * Administrative functionality * Authenticated APIs * Unauthenticated APIs * Backend-connected functionality 2. Mobile Application Security Perform security testing of the mobile application, including the underlying APIs and backend services. The testing should not be limited to the mobile interface. The APIs should be manually tested to determine whether requests can be modified to access unauthorized information or functionality. 3. API Security Test the APIs for: * Broken authentication * Broken authorization * IDOR * BOLA * Privilege escalation * Authentication bypass * Authorization bypass * Parameter tampering * Request manipulation * Mass assignment * Excessive data exposure * Missing authorization checks * HTTP method manipulation * Sensitive information exposure * Improper error handling * Exposed internal endpoints * Debug or test endpoints * Unprotected APIs * Excessive permissions 4. Access Control Testing Test different user roles and verify that access restrictions are correctly implemented. At minimum, test: * Unauthenticated user * Normal User A * Normal User B * Administrator Verify that users can only access resources and perform actions that they are authorized to access. 5. Database and Backend Security Assess whether unauthorized users can directly or indirectly access database information through the application’s APIs or backend. Check for: * Exposed database credentials * Public database access * Unauthorized database records returned through APIs * Missing backend authorization * Access to other users’ records * Unauthorized modification of records * Unauthorized deletion of records * Excessive backend permissions * Exposed sensitive information * Insecure service-account permissions 6. Cloud and Server Security If the application uses AWS, Firebase, or other cloud services, review relevant security configurations. Check for: * Publicly accessible databases * Public storage * Exposed credentials * Over-permissioned IAM roles * Incorrect security group configuration * Unnecessary open ports * Exposed environment variables * Exposed API keys or secrets * Insecure database security rules * Insecure storage permissions * Publicly accessible backend services 7. Mobile Application Security Where applicable, check for: * Hardcoded credentials or secrets * Exposed API keys * Insecure local storage * Sensitive information stored insecurely * API authentication weaknesses * Certificate/transport security issues * Client-side security controls that can be bypassed * Reverse engineering risks * Unauthorized API access through modified requests Expected Deliverables I expect a professional security audit report containing: 1. Executive Summary Overall assessment of the application’s security condition. 2. Vulnerability Report For each vulnerability: * Vulnerability name * Severity: Critical, High, Medium, Low, or Informational * Affected application * Affected endpoint/component * Description * Security impact * Steps to reproduce * Evidence/screenshots where appropriate * Recommended fix * Verification method 3. Authorization Matrix Provide a clear matrix showing which user roles can access important resources and functionality. 4. API Security Assessment List important APIs tested and whether proper authentication and authorization are enforced. 5. Database Access Assessment Clearly state whether a normal user can access unauthorized database information directly or indirectly through the application. 6. Remediation Recommendations Provide practical recommendations that developers can use to fix the identified issues. 7. Retesting After vulnerabilities are fixed, a retest may be required to confirm that the vulnerabilities have been properly resolved. Important Requirements I am not looking for someone who only runs an automated vulnerability scanner and provides a generic report. The project requires manual security testing in addition to automated tools. The freelancer should have strong e

تابع القراءة مجانًا

أنشئ حسابًا مجانيًا لعرض الوظيفة كاملة والتقديم عليها.

  • badgeملف مرئي للشركات
  • notificationsتنبيه بالوظائف الجديدة عبر البريد الإلكتروني
  • favoriteمجاني دائمًا، بلا خدع