
Closed
Posted
Paid on delivery
I need an experienced ethical hacker to conduct thorough penetration testing on my mobile applications. The sole focus of this engagement is to simulate real-world attacks, uncover security flaws, and document practical remediation steps. Scope of work • Plan and execute a full penetration test tailored to mobile environments—covering authentication, data storage, API calls, transport security, reverse engineering, and runtime manipulation. • Use industry-standard methodologies such as the OWASP Mobile Security Testing Guide and well-known tools (e.g., Burp Suite, Frida, MobSF, Wireshark, Kali). • Provide a clear, reproducible report that ranks vulnerabilities by severity, explains exploitation paths, and recommends fixes that developers can act on immediately. Acceptance criteria 1. All discovered issues include proof-of-concept evidence (screenshots, logs, or step-by-step reproduction). 2. The final report follows CVSS scoring and maps findings to OWASP Mobile Top 10. 3. A debrief session (voice or video) to walk through the results and answer developer questions is completed. Let me know your estimated timeline, any device or OS version requirements you have for testing, and a brief outline of your previous mobile app pentest experience.
Project ID: 40621446
18 proposals
Remote project
Active 6 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
18 freelancers are bidding on average ₹9,989 INR for this job

Hello, I am an experienced Ethical Hacker, Mobile Application Penetration Tester, and Digital Forensics Investigator with over 9 years of cybersecurity experience. I have performed security assessments on Android and mobile applications using OWASP MSTG methodologies and tools including Burp Suite, Frida, MobSF, JADX, APKTool, Wireshark, Kali Linux, and ADB. For this engagement, I will conduct a comprehensive mobile application penetration test covering authentication, insecure data storage, API security, transport security, reverse engineering, SSL pinning/runtime manipulation, and other mobile-specific attack vectors. Every finding will include reproducible proof-of-concept evidence, CVSS scoring, OWASP Mobile Top 10 mapping, detailed remediation guidance, and a professional report suitable for your development team. I am also available for a voice/video debrief session to walk through the findings and answer technical questions. Testing environment: Android 10–15 physical devices and emulator support. iOS testing can also be accommodated if required. I have extensive experience performing security assessments for Android applications, APIs, enterprise platforms, and web applications, delivering actionable reports that help organizations remediate vulnerabilities before production deployment.
₹7,000 INR in 7 days
5.3
5.3

Hi, I am Haresh, having 14+ years of experience in Software Testing Industry. - Having unique blend of knowledge in Quality Product Delivery, Processes Management, Functional testing, Integration and regression testing, load and Perfromance Testing which help me to take the Quality of the software to the next level. - Hands on experience on testing Desktop, Web Based, Mobile application and ERP based application. - Hands on experience on automation testing tools on selenium webdriver, jmeter, katalon studio, Appium, cypress, selenium with TestNG freamwork etc.. - Thorough understanding of Product Delivery Life Cycle, Software Testing Life Cycle and Software Development Life Cycle. - Experience in Well conversant with writing Test plan,Test Cases,Bug report, Release Note and Product Health Report. - Worked in various domains like Finance, Retail, Web Portals, Healthcare, ecommnerce, CMS, Eduction Portal, Life Insurance, ERP system etc. - I do have require mobile devices to test mobile view or applications like android and iOS applications. - I have hands on experience with Git, postman, MSSQL Server. Kindly review my profile and let me know you view over the same. Thanks, Haresh
₹15,000 INR in 7 days
5.1
5.1

This project immediately caught my attention because it is exactly the type of work I do best. Your need for thorough penetration testing on mobile applications, focusing on authentication, data storage, and transport security, aligns perfectly with my expertise in delivering clean, professional, and user-friendly security assessments. While I am new to freelancer, I have tons of experience and have done other projects off site, utilizing industry-standard methodologies like the OWASP Mobile Security Testing Guide and tools such as Burp Suite and Frida. If this sounds like what you're looking for, I'd love to hear more about your project. Regards, Warrick Van Eeden
₹5,650 INR in 7 days
0.0
0.0

Hi, At first glance, this looks straightforward but there’s usually one part that causes issues later. Happy to share a quick plan if you're open to it. Regards, Rajesh
₹7,000 INR in 7 days
0.0
0.0

As an ethical hacker with a strong background in computer security and penetration testing, I am confident that I am the best fit for your mobile app testing project. My primary goal is to provide not just a list of vulnerabilities but also practical remediation steps that your developers can act on immediately. With extensive experience using industry-standard methodologies such as the OWASP Mobile Security Testing Guide and notable tools including Burp Suite, Frida, MobSF, Wireshark, and Kali, I am well-equipped to simulate real-world attacks, detect even hidden security flaws, and generate clear-cut reports that follow CVSS scoring standards. One of my distinctive advantages lies in my provision of reproducible evidence for all discovered issues using screenshots, logs or step-by-step reproduction. Combining my expertise in Certified Information Systems Security Professional (CISSP) and Risk Management, your mobile applications will undergo not only a thorough attack simulation but also an analysis that ranks vulnerabilities by severity and maps findings to OWASP Mobile Top 10. To ensure you have full clarity on the entire process and results, I'll be delighted to arrange a debrief session (voice or video) wherein we can walk through the results together and address any inquiries you might have. Basically, I hold an unwavering commitment to timeliness and quality so you are guaranteed both timely delivery and unlimited efforts towards 100% satisfaction.
₹12,500 INR in 1 day
0.0
0.0

I can help you uncover security flaws in your mobile applications, ensuring they are fortified against real-world attacks. The details about focusing on a comprehensive assessment tailored to mobile environments really stood out to me. My approach involves meticulous planning and execution, utilizing industry-standard methodologies like the OWASP Mobile Security Testing Guide. I’m familiar with key tools such as Burp Suite and Frida, which allows me to simulate various attack vectors effectively. I have done similar work: Modern Real Estate Investment Website (link). This project involved a detailed examination of security vulnerabilities and providing actionable remediation steps. Let’s chat about your specific requirements and timeline. At the very least, you’ll get a free consultation to discuss the best approach for your project. Regards, Dean
₹5,650 INR in 7 days
0.0
0.0

Hi, I am an experienced QA Engineer with expertise in Mobile Application Testing and Penetration Testing. I can perform comprehensive security testing to identify vulnerabilities such as insecure authentication, insecure data storage, API security issues, OWASP Mobile Top 10 risks, and other potential security flaws. I will provide a detailed report with identified vulnerabilities, risk severity, proof of concept, and actionable remediation recommendations. I am committed to delivering accurate results while maintaining confidentiality and ensuring high-quality work. I am available to start immediately and look forward to helping secure your mobile application.
₹7,000 INR in 7 days
0.0
0.0

Hello, I can perform a comprehensive security assessment of your mobile application following the OWASP Mobile Security Testing Guide (MSTG). My testing will include: * Authentication and authorization testing * Secure data storage analysis * API security assessment * SSL/TLS and certificate pinning validation * Reverse engineering and static analysis * Runtime testing using Frida * Manual testing with Burp Suite and Kali Linux * Verification of discovered vulnerabilities with proof of concept You will receive a professional penetration testing report including: * Executive Summary * Technical Findings * CVSS Severity Rating * OWASP Mobile Top 10 Mapping * Step-by-step reproduction * Screenshots and evidence * Practical remediation recommendations I have hands-on experience with Burp Suite, Frida, MobSF, JADX, ADB, Android Studio, and API security testing. I also have practical experience performing web and mobile security assessments using industry-standard methodologies. Estimated timeline: 5 days. To begin, I will need: * APK (or source if available) * Test account(s) * Target Android version (or supported versions) * Any specific areas you would like me to focus on I will also be available for a debrief session to explain all findings and answer your developers' questions. I look forward to working with you. Best regards, Kareem
₹5,000 INR in 5 days
0.0
0.0

Hello, I am interested in your mobile application security testing project. I have experience in mobile app testing and QA, and I am eager to assist with structured testing and documentation. I can carefully follow your testing requirements, communicate regularly, and deliver clear reports with screenshots and detailed findings. Before starting, I would like to discuss the target platform (Android/iOS), supported OS versions, and the testing scope to ensure all requirements are covered. I am available to start immediately and committed to delivering reliable, professional work.
₹7,000 INR in 7 days
0.0
0.0

Hi, I’m an application security professional with 10+ years in InfoSec, specializing in mobile app penetration testing (CEH v12, Burp Suite Certified Practitioner). Your scope is exactly my focus. I’ll test against the OWASP MSTG — covering authentication, insecure data storage, API security (IDOR, broken auth, rate limiting), transport security, reverse engineering, and runtime manipulation (SSL pinning bypass via Frida/Objection). Tools: Burp Suite, Frida, MobSF, jadx, apktool. You’ll get a clear, reproducible report — every finding scored by CVSS, mapped to the OWASP Mobile Top 10, with proof-of-concept evidence (screenshots + step-by-step reproduction) and developer-actionable remediation. Timeline: 5 days from receiving the build. Quick question: is this Android, iOS, or both? And can you share the APK/IPA plus any target OS versions?
₹10,000 INR in 5 days
0.0
0.0

I'm a penetration tester with 6+ years in application security — OSCP & CRTO certified, currently Senior Associate at PwC leading Web/Android/Network security assessments, previously Consultant at EY performing mobile pentesting aligned to OWASP Mobile Top 10. I've identified high-severity issues including RCE, IDOR, SQLi, and auth bypass on production apps. Approach (aligned to OWASP MASTG, Android-focused): Static + dynamic analysis via MobSF, Frida, Objection API/transport security testing via Burp Suite, Wireshark Auth, session, and local data storage review Reverse engineering & runtime manipulation (root detection bypass, SSL pinning bypass) Full mapping to OWASP Mobile Top 10 with CVSS-scored, PoC-backed findings (screenshots/logs/repro steps) Developer-actionable remediation guidance Live debrief call post-report to walk through findings Timeline: 4–5 working days for the Android application. Device/OS: Testing on a rooted Android device/emulator — please confirm target Android OS version(s) for compatibility. Scope note: I specialize in Android; if you also need iOS covered, happy to discuss options, otherwise this covers Android end-to-end. Experience: Hands-on Android app pentesting at PwC and EY, using MobSF/Frida/Objection with OWASP MASTG methodology. Happy to share a redacted sample report before starting. Shouvik Dutta OSCP | CRTO | CEH v11
₹11,500 INR in 5 days
0.0
0.0

Recently worked on Java Rest Assured-Spring… Python (3 yrs. ):- Worked on python-selenium, python API automation, earlier used python unit test framework (API) and Junit with Mockito for Unit Testing of application. Overall, Python Selenium (UI), Python API automation – altogether 3 years… Java( 3 yrs ):- Junit – 6 months earlier, Selenium with Java,REST Assured automation – 2.5 years
₹7,000 INR in 7 days
0.0
0.0

Hello! I am happy to help you perform a thorough and practical penetration test of your mobile applications. Method & Experience I have good experience in mobile security auditing on both Android and iOS. The work is carried out strictly according to the OWASP Mobile Security Testing Guide (MSTG) with industry standard tools such as Burp Suite, Frida, MobSF, Wireshark and Kali Linux. Tests cover the entire chain: • Static & dynamic analysis (secure data storage, source code, reverse engineering). • Runtime manipulation (bypassing SSL pinning, root/jailbreak detection with Frida). • Network & API (encryption, sessions, transport layer). Delivery • Clear report where findings are mapped against the OWASP Mobile Top 10 and CVSS scored. • Step-by-step Proof-of-Concept (PoC) with screenshots/logs so that developers can easily reproduce and fix the flaws. • Final debrief call for review and questions. Requirements & Time Estimate • Devices: Tests are performed on Android (10–14, rooted/unrooted) and iOS (15–17, jailbroken/standard). • Resources: Requires APK/IPA files, test accounts, and any API docs. • Time: Typically 3–5 business days per app. Get in touch and we'll get started!
₹20,000 INR in 10 days
0.0
0.0

OSCP-certified Penetration Tester with over 3 years of experience performing comprehensive security assessments for web applications, APIs, mobile applications (Android & iOS), and network environments. Skilled in identifying, validating, and reporting vulnerabilities aligned with the OWASP Top 10, API Security Top 10, and industry best practices. Experienced in manual penetration testing, security verification, vulnerability assessment, exploit validation, and delivering detailed remediation guidance. Proficient with tools such as Burp Suite, Nmap, Metasploit, Nessus, Wireshark, SQLMap, and OWASP ZAP. Committed to helping organizations strengthen their security posture through practical, risk-focused assessments and clear, actionable reporting.
₹9,000 INR in 7 days
0.0
0.0

I am a penetration tester at Deloitte. Owner of 5 CVEs, experienced in identifying vulnerabilities through bug bounty programs, holding the eWPTXv3 certification, and currently expanding skills in Active Directory, Mobile, and Kubernetes Security, as well as CCNA-level networking. I have strong skills in mobile security, also passionate about ethically hacking mobile applications
₹5,500 INR in 5 days
0.0
0.0

Hello, I have **10+ years of experience** in Application Security, Penetration Testing, API Security, Cloud Security, and Secure Development. I perform mobile security assessments following **OWASP MSTG**, **OWASP Mobile Top 10**, and **CVSS** standards. My testing covers: • Authentication & Authorization • API Security (Burp Suite) • Local Data Storage • Transport Security (TLS/SSL) • Reverse Engineering (APK/IPA) • Runtime Analysis (Frida/Objection) • Root/Jailbreak Detection Bypass • Business Logic Testing • Static & Dynamic Analysis (MobSF) I also have experience in **AI Red Teaming**, including **Prompt Injection, Jailbreak Testing, System Prompt Extraction, Data Leakage, Indirect Prompt Injection**, and validation against the **OWASP Top 10 for LLM Applications**. **Deliverables:** ✔ Executive & Technical Report ✔ CVSS Severity Ratings ✔ OWASP Mobile Top 10 Mapping ✔ PoC Screenshots & Reproduction Steps ✔ Practical Remediation Recommendations ✔ Debrief Session with Developers **Timeline:** • Small App: 5–7 Days • Medium App: 10–12 Days • Large App: 12–15 Days **Requirements:** APK/IPA, test accounts, staging environment (preferred), and supported Android/iOS versions. I use industry-standard tools including **Burp Suite Pro, Frida, MobSF, Wireshark, Kali Linux, JADX, APKTool, Objection, and Nmap** to simulate real-world attacks and deliver actionable security findings. Looking forward to working with you.
₹35,000 INR in 15 days
0.0
0.0

Hello, I am a QA Tester with experience in mobile application testing, functional testing, regression testing, and defect reporting. While my primary expertise is software quality assurance rather than advanced penetration testing, I can assist with validating authentication flows, user access testing, API behavior validation, session handling checks, and identifying functional security concerns from an end-user perspective. I provide detailed defect reports with reproduction steps, screenshots, expected vs. actual results, and recommendations for resolution. Regards, Srivani Annaladasu QA Tester
₹7,000 INR in 4 days
0.0
0.0

Hello, I can perform an authorized security assessment for one mobile application within the scope you approve. My work focuses on Android reverse engineering, runtime analysis, API security testing, and actionable remediation reporting. For this engagement, I will assess authentication and session handling, insecure local storage and logging, exported components/deep links, TLS and API communication, authorization issues, and relevant runtime attack surfaces. I will validate findings manually and map confirmed issues to CVSS and OWASP Mobile Top 10 / MASTG guidance. Deliverables within 5 days: • concise test plan and confirmed in-scope targets • reproducible technical report with severity, evidence, reproduction steps, and remediation guidance • PoC screenshots/logs for confirmed findings • short debrief call after delivery To begin, I need written authorization, the APK/IPA or approved test build, test accounts, approved API hosts, and a non-production or explicitly authorized testing environment. My bid covers one app and the supplied authorized scope only; I will not access unrelated production data or perform disruptive testing. I can start once the scope and access are confirmed.
₹3,000 INR in 5 days
0.0
0.0

Daman, India
Member since Aug 2, 2026
₹1500-12500 INR
₹12500-37500 INR
₹12500-37500 INR
₹750-1250 INR / hour
$250-750 USD
$250-750 USD
$25-50 USD / hour
₹12500-37500 INR
₹1500-12500 INR
₹4500-5000 INR
₹600-1500 INR
$30-250 USD
$750-1500 USD
$30-250 USD
$30-250 USD
£20-250 GBP
₹600-1500 INR
₹600-1500 INR
$3000-5000 USD
$30-250 USD