
Closed
Posted
Paid on delivery
I run a set of paper-trading websites and companion mobile apps and I need a seasoned ethical hacker to put them through a full-scale penetration test right away. The single goal is to assess their overall security: break in if you can, show me exactly how you did it, and tell me how to close every gap you discover. You will have production-like credentials and enough time to perform reconnaissance, exploitation, privilege escalation, and post-exploitation analysis. I expect a concise report that ranks each finding by risk, reproduces the steps taken, and recommends clear fixes I can hand straight to my developers. Any tooling is fine—Burp Suite, OWASP ZAP, Kali Linux, custom scripts—so long as the results are thorough and defensible. I need this done ASAP, so please reply with a brief overview of your relevant experience in penetration testing or bug-bounty style work. If you are confident you can breach a system responsibly and document everything to industry standards, let’s get started.
Project ID: 40516976
8 proposals
Remote project
Active 6 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
8 freelancers are bidding on average ₹170,000 INR for this job

I'm Constantin, a seasoned Certified Ethical Hacker with deep expertise in network security and penetration testing. Over the past 7+ years, I've honed my skills in breaching systems legally, whether it be web apps, APIs, cloud infrastructure or internal networks. My focus isn't on merely ticking checkboxes but on thinking like an attacker, which has helped me find critical zero-days before they cause harm. One of my key strengths is translating complex findings into clear, actionable insights that will help you close any security gaps immediately. My clients rely on me to deliver concise reports that rank each finding by risk, reproduce the steps taken and provide actionable recommendations. I can provide this same value for your paper-trading websites and companion mobile apps. My qualifications speak volumes about my capabilities: CEH, OSCP, CISSP, PNPT, eWPT - an extensive array of certifications in the field that have prepared me to handle the toughest break-ins. You needn't worry about tooling either - I'm proficient with popular tools like Burp Suite, OWASP ZAP, Kali Linux and more and even have experience with custom scripts if need be. My commitment is to intensively test your system to detect any vulnerabilities and furnish thorough results to fortify your applications better than ever.
₹200,000 INR in 7 days
5.2
5.2

Hello, I am a Cyber Security & Digital Forensics professional with 9+ years of experience in Penetration Testing, Vulnerability Assessment, API Security, Mobile Application Security, and Digital Investigations. I have performed black-box, grey-box, and authenticated security assessments for web applications, mobile apps (Android/iOS), APIs, cloud environments, and enterprise infrastructures. For your paper-trading platforms, I can conduct a comprehensive penetration test covering reconnaissance, authentication controls, business logic flaws, privilege escalation, API security, session management, OWASP Top 10 vulnerabilities, and post-exploitation analysis. All findings will be validated manually, ranked by risk severity, and documented with proof-of-concept evidence, exploitation steps, impact assessment, and detailed remediation guidance. Deliverables include a professional penetration testing report, executive summary, technical findings, CVSS-based risk ratings, and developer-friendly mitigation recommendations. I am available to start immediately and can provide a thorough, industry-standard assessment within your required timeline. Best Regards, Kajal Majhi Cyber Security & Digital Forensics Specialist
₹200,000 INR in 7 days
5.1
5.1

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive penetration test of your paper-trading web platforms and mobile applications. Relevant Experience • Extensive experience in web, mobile, API, and SaaS security assessments • Proven track record in identifying authentication flaws, privilege escalation paths, business logic vulnerabilities, IDORs, and API security issues • Experience with bug bounty-style testing and real-world attack simulation Approach • Full attack surface assessment including reconnaissance, exploitation, privilege escalation, and post-exploitation validation • Manual + automated testing aligned with OWASP Top 10, OWASP Mobile Top 10, and PTES • Tools: Burp Suite, OWASP ZAP, MobSF, Frida, Nmap, Metasploit, and custom scripts Deliverables • Risk-ranked penetration testing report with CVSS severity ratings • Detailed reproduction steps and PoC evidence • Clear remediation guidance for developers • Executive summary for management We focus on real exploitable vulnerabilities rather than automated scan results and can start immediately upon receiving access and scope details.
₹155,000 INR in 7 days
3.6
3.6

Hello, I am a Cybersecurity Analyst and Penetration Tester with experience in Web Application Security, API Security Testing, Vulnerability Assessment, and Incident Response. I can perform a comprehensive security assessment of your paper-trading websites and mobile applications to identify vulnerabilities before deployment. My approach combines manual testing and industry-standard methodologies to uncover issues that automated scanners often miss. The assessment will cover: • Authentication and authorization testing • Session management review • API security testing • Business logic vulnerabilities • Privilege escalation checks • Input validation and injection testing • Sensitive data exposure review • OWASP Top 10 vulnerabilities • Mobile and web application security testing I use tools such as Burp Suite, OWASP ZAP, Nmap, Wireshark, Postman, Kali Linux, SQLMap, and custom Python scripts where appropriate. Deliverables include a detailed penetration testing report with risk-ranked findings, proof-of-concept evidence, reproduction steps, impact assessment, and practical remediation recommendations. I provide regular progress updates and can begin immediately. Before starting, I would appreciate clarification regarding the number of applications, APIs, user roles, and environments included in scope. I look forward to helping strengthen the security of your platform. Thank you.
₹150,000 INR in 7 days
0.0
0.0

Your paper-trading web + mobile apps need a structured pentest with risk-ranked findings — exactly what we can deliver as a team that builds and breaks web/mobile stacks daily. We'll run recon, exploitation, privilege escalation and post-exploitation across your web app and mobile APIs, using Burp Suite, OWASP ZAP, and custom scripts. Deliverable: a clear report your devs can act on immediately. Ping me to discuss scope and timeline.
₹175,000 INR in 14 days
0.0
0.0

Hi. I approach a web and mobile app the way an attacker would: map the surface, find where the trust assumptions break, and prove the impact rather than just flag a scanner warning. A full-scale test of your paper-trading sites and companion apps, with a clean report your developers can act on, is the kind of engagement I'm set up for. From the brief you want real reconnaissance, exploitation, privilege escalation and post-exploitation, then a concise report that ranks each finding by risk, reproduces the steps and gives fixes you can hand straight to your devs. I'd run it methodically, OWASP-style, across auth and session handling, access control and IDOR between accounts, and the trading and order flows where business-logic abuse usually hides (price and quantity tampering, race conditions on order placement, balance manipulation), plus the API layer behind the apps and the mobile clients for hardcoded secrets and insecure storage. Burp Suite and ZAP for the web and API work, Kali and custom scripts where it needs them. Everything against the production-like credentials you provide, scoped and responsible, each finding evidenced so it holds up rather than hand-waved. What you get is a prioritised report that shows how each gap was reached and exactly how to close it, written for your developers to action straight away. I can start on reconnaissance as soon as you share the scope and credentials.
₹180,000 INR in 14 days
0.0
0.0

Hello, I am a Cyber Security Research Engineer with 6+ years of experience in Web, API, and Mobile Application Penetration Testing. I have extensive bug bounty experience and have identified vulnerabilities such as IDOR, XSS, SSRF, Authentication Bypass, RCE, and Privilege Escalation. I can perform a complete penetration test of your web and mobile platforms, including OWASP Top 10 testing, authentication and authorization testing, business logic testing, privilege escalation, and post-exploitation analysis. A detailed report with proof-of-concept findings, risk ratings, and remediation recommendations will be provided. I can complete your project for ₹40,000 and am ready to start immediately. Regards, Rohit Kumar
₹150,000 INR in 3 days
0.0
0.0

We've just completed a similar project. We recently helped someone achieve a similar objective and outcome. Explain how we can help them achieve their goal with a professional and reliable solution. I have completed many projects outside Freelancer.com and am currently offering discounted rates to build my reputation here. Payment is only required if the final work meets the agreed scope and requirements. I'd love to chat about your project! The worst that can happen is you walk away with a free consultation. Regards, Jabu.
₹150,000 INR in 7 days
0.0
0.0

Ahmedabad, India
Member since Jun 5, 2026
₹12500-37500 INR
$150-200 USD
₹12500-37500 INR
$30-250 USD
$250-750 USD
₹1500-12500 INR
$3000-5000 NZD
$15-25 USD / hour
$250-750 USD
₹12500-37500 INR
₹1500-12500 INR
₹12500-37500 INR
$250-750 USD
$25-50 USD / hour
₹12500-37500 INR
₹600-1500 INR
₹1500-12500 INR
₹1250-2500 INR / hour
₹1500-12500 INR
$20000-35000 USD