Find Jobs
Hire Freelancers

Pentration testing of our web site

$15-25 AUD / hour

Dokončeno
Zveřejněno skoro před 6 roky

$15-25 AUD / hour

We would like an experienced person to perform penetration testing of our web site. this is the scope of work This is very urgent. Scope of Work. The Freelancer will perform an Application Penetration Testing to identify vulnerabilities in applications residing on Customer’s networked systems that offer user or inter-process interfaces, such as web applications and “thick” clients. The Application Penetration Testing will examine Customer’s application’s components and technologies to identify vulnerabilities in systems, server systems, static content, and server-side programs that implement the application logic. The Freelancer will identify common and more unique application flaws. The Freelancer will test for common application flaws, such as stack overflows and format string issues. In addition, The Freelancer will examine the application’s underlying design for unique vulnerabilities that may not be easily recognizable during a more superficial investigation. The Freelancer will perform a variety of checks, based on industry-specific guidance, industry practices and standards. As determined necessary by The Freelancer, application components will be tested for improper configuration, session tracking weaknesses, encryption implementation and strength, input validation, flaws in server-side executables, and sensitive or unnecessary information within HTML content. The Freelancer will perform application security testing of the Customer’s applications through automated web application scanning as well as manual application functionality testing. The Freelancer’s testing techniques will consist of: · Input validation bypass – The Freelancer will remove client side validation routines and bounds-checking restrictions to confirm controls are implemented on application parameters sent to the server. · SQL injection – The Freelancer will submit specially crafted SQL commands in input fields to validate input controls are in place for the protection of database data. · Cross-site scripting – The Freelancer will submit active content to the application in an attempt to cause a user's web browser to execute unauthorized and unfiltered code. This test is meant to validate user input controls. · Parameter tampering - The Freelancer will modify query strings and parameters, and hidden fields in an attempt to gain unauthorized access to user data or application functionality. · Cookie poisoning – The Freelancer will modify data sent in cookies in order to test application response to receiving unexpected cookie values. · User privilege escalation – The Freelancer will attempt to gain unauthorized access to administrator or other users’ privileges. · Credential manipulation – The Freelancer will modify identification and authorization credentials in an attempt to gain unauthorized access to other users’ data and application functionality. · Forceful browsing – The Freelancer will enumerate files located on a web server in an attempt to access files and user data not explicitly shown to the user within the application interface. · Backdoors and debug options –The Freelancer will identify code left by developers for debugging purposes that could potentially allow an intruder to gain additional levels of access. · Configuration subversion –The Freelancer will assess Customer’s web servers and application servers for improper configurations that could create attack vectors. · Test Environments – Some Applications (as defined below) to be tested will be in a Customer test or development environment.
IČ projektu: 17291809

O projektu

9 nabídky
Vzdálený projekt
Aktivní před 6 roky

Chcete si vydělat nějaké peníze?

Výhody podávání nabídek na Freelancer

Stanovte si rozpočet a časový rámec
Získejte za svou práci zaplaceno
Načrtněte svůj návrh
Registrace a podávání nabídek je zdarma
Uděleno:
Avatar uživatele
QA|Software|Security|Testing|QMR|Project Management|Scrum Master|Test Lead Software Testing for almost 10 years of experienced. - Experienced in Testing of Web, desktop, mobile Apps, (such as Iphone & Android Technologies) - Experienced to develop automation in Selenium IDE and webDriver with java. - Experienced to control Hacking & provide security as well as control vulnerabilities Cross site Script, SQL injection, Blind injection, CSRF, Brute Force attack and etc, with the help of tools as well as manually script based testing. - Experienced in load/performance/stress testing use different tools specifically jmeter and Google analyzer. - Experienced in black, white, review, Performance, security, load, regression, usability, functional, unit, stress and various testing methods. - Develop Wire-frames, Scope document, test plans, test cases, SRS (software requirement specification), FS (Functional specification), Test Release, test Matrix, Bug Report etc as well as look after the project management side. - Experienced to work as scrum Master and managing in “JIRA” for reporting, Demonstrating and managing team issues (task, story and bugs) etc. Education & Certification Masters in Computer Science (MCS)
$22 AUD v 40 dnech
5,0 (25 recenze)
4,8
4,8
9 freelanceři nabízejí v průměru $20 AUD/hodinu za tuto práci
Avatar uživatele
Hi, I can complete this task. Please share more details with me. We can have a chat for further discussion. Completed Msc in Cyber Security. I have two bachelor degrees (Networking and Computer Science). And I have CCNA and RHCSA certifications. Currently working as an Information Security Engineer. Thank You.
$22 AUD v 40 dnech
5,0 (18 recenze)
4,1
4,1
Avatar uživatele
Hello, Senior. How are you? I have experience 7+ years in developing .NET, Laravel, node.js, angular.js, react.js and Python Frameworks. Additionally, I have experience in Android and iPhone. I will work for you all my best. Thank you in advance for your time and consideration. I look forward to working with you soon. - Laravel, WordPress, Codeigniter, Django. - .NET, JavaScript, PHP, Node JS, Angular.js, React.js. - C++, Java, C#, Python, Web Scrapping. - Android, Object C, Swift, ionic
$30 AUD v 40 dnech
4,6 (2 recenze)
3,3
3,3
Avatar uživatele
Hello, I can take this job, the total fee is ~ 2500 $ Look my profile please, I ready to answer any your questions.
$22 AUD v 40 dnech
5,0 (2 recenze)
2,2
2,2
Avatar uživatele
I have been working as QC tester for around a year now, still junior but i can detect most bugs on your website.
$15 AUD v 40 dnech
0,0 (0 recenze)
0,0
0,0
Avatar uživatele
i am qualified in CEH security exam . for long time am in this filed
$22 AUD v 10 dnech
0,0 (0 recenze)
0,0
0,0
Avatar uživatele
Consolidating my past involvement in AWS,Azure Administration,Ethical Hacking, Incident Response, IT Security Governance, and Project Management with solid relational and correspondence capacities, I am sure that I can give work that will surpass your desires. Security Analyst with 6 years' experience in Endpoint security, Application Security, Change Management, Exception Handling and VAPT. Experience in system and network administration, managing server infrastructures and data center operations. Security Tools: Nessus, Nmap, burp suite, Wire shark, Web scarab. Operating Systems & Platform: Kali Linux, Backtrack 5 r3, Windows 7, 8, 8.1,10, MAC. Programming Language: HTML, JavaScript. Framework: Metasploit, OWASP. Endpoint: Sophos, Check Point.
$15 AUD v 40 dnech
0,0 (0 recenze)
0,0
0,0

O klientovi

Pochází z AUSTRALIA
Sydney, Australia
5,0
12
Ověřená platební metoda
Členem od kvě 26, 2011

Ověření klienta

Díky! Poslali jsme vám e-mailem odkaz pro získání kreditu zdarma.
Při odesílání e-mailu se něco pokazilo. Zkuste to prosím znovu.
Registrovaných uživatelů Zveřejněných projektů
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Načítání náhledu
Bylo uděleno povolení ke geolokaci.
Vaše doba přihlášení vypršela a byli jste odhlášeni. Přihlaste se znovu.