arrow_back العودة إلى الأعمال الحرة
F

E-Procurement Web App Penetration Test

Freelancer

مشاركة:
placeZA home_workعن بُعد assignmentبعقد publicوظيفة مجمّعة · ZA

eventنُشرت في 30 أغسطس 2026 · verifiedتحققنا في 31 أغسطس 2026 من أنها ما زالت متاحة

US$ 30 – US$ 250 / لكل مشروع

عن الوظيفة

I run a custom-built e-procurement platform (PHP, Bootstrap front-end, MySQL) hosted on a private AlmaLinux VM and administered through DirectAdmin. Before pushing new features live, I need a thorough penetration test that zeroes in on web-application weaknesses. Please quote separately for a Black-Box assessment (no internal knowledge) and a Grey-Box assessment (limited credentials or code snippets provided). The goal is to understand how each testing style changes the risk picture and the remediation roadmap. Scope of the engagement • Authentication & authorization • Input validation & sanitization • Session management You may explore any additional vectors necessary to fully cover those three areas, but infrastructure, network layers, and the database engine itself are outside today’s brief unless they directly impact the web layer. Required deliverables 1. Concise executive summary suitable for non-technical stakeholders. 2. Detailed technical report with step-by-step findings, proof-of-concept evidence, CVSS scoring, and prioritized remediation guidance. 3. Retest verification list so we can confirm fixes in a follow-up sprint. I’m comfortable with widely accepted tools such as Burp Suite, OWASP ZAP, sqlmap, and custom scripts—use whatever produces reliable, repeatable results and note all tooling in the report. Let me know the estimated timeline, required prerequisites, and the two separate price quotes so we can lock in the engagement. Application: https://eprocurement.wemasoft.net/ Access: sanele / $S4n3l3@2026!#

تابع القراءة مجانًا

أنشئ حسابًا مجانيًا لعرض الوظيفة كاملة والتقديم عليها.

  • badgeملف مرئي للشركات
  • notificationsتنبيه بالوظائف الجديدة عبر البريد الإلكتروني
  • favoriteمجاني دائمًا، بلا خدع