
Closed
Posted
I need a seasoned ethical hacker to run a controlled penetration test on two specific assets I own: 1) my network infrastructure and 2) the user-login / authentication flow of my e-commerce site. You will receive explicit written authorisation before we begin, and I am happy to sign an NDA in return. Scope in brief • Network infrastructure – map the attack surface, probe firewalls, routers and wireless segments, attempt privilege escalation and highlight any misconfigurations. • E-commerce site – focus strictly on the login and session handling mechanisms, checking for issues such as brute-force resistance, session fixation, password-reset flaws and other OWASP Top-10 vulnerabilities. (Payment gateway and database layers are out of scope for now; we can expand later.) Acceptance criteria & deliverables • Pre-engagement testing plan for my sign-off • Penetration-test report (PDF) that includes CVSS scores, proof-of-concept evidence and clear remediation steps • Optional debrief call to walk through findings Kindly include in your proposal: – A brief overview of comparable projects you have completed – Any relevant certifications (OSCP, CEH, CISSP, etc.) – Your estimated timeline and a cost breakdown for reconnaissance, exploitation and reporting phases Familiarity with common toolsets—Nmap, Burp Suite, Metasploit, Wireshark or equivalents—will be assumed. I’m ready to start as soon as we align on scope and schedule.
Project ID: 40600481
23 proposals
Remote project
Active 7 mins ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
23 freelancers are bidding on average ₹4,061 INR/hour for this job

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
₹5,500 INR in 40 days
6.0
6.0

Hello, I hold a BSc degree in Computer Science and have experience in security assessments, vulnerability analysis, and penetration testing methodologies. I understand the importance of working only under written authorization and within an agreed scope. For this project, I will: • Prepare a pre-engagement testing plan for your approval. • Assess your network infrastructure for exposed services, firewall/router misconfigurations, wireless security issues, and privilege escalation risks. • Test your e-commerce authentication flow for OWASP Top 10 vulnerabilities, including brute-force protection, session management, session fixation, password reset, and authentication weaknesses. • Deliver a professional report with CVSS risk ratings, proof-of-concept evidence, and prioritized remediation recommendations. • Conduct a debrief session to explain findings if required. I am familiar with tools such as Nmap, Burp Suite, Metasploit, and Wireshark, and I follow responsible testing practices. I respect confidentiality and am happy to sign an NDA before work begins. I am available to start immediately and look forward to discussing the scope, timeline, and deliverables.
₹5,500 INR in 40 days
5.7
5.7

? Certified AWS Solutions Architect – Professional ? Certified AWS Solutions Architect – Associate ? CISA Certified Security Expert ? 16+ Years of Experience in Cybersecurity, DevSecOps & Infrastructure Security Hi there, I'd be happy to perform a controlled penetration test on your network infrastructure and e-commerce authentication flow. With 16+ years of experience in offensive security, network security, and web application testing, I follow industry-standard methodologies aligned with OWASP, NIST, and PTES. How I Can Help • Network reconnaissance and attack surface assessment • Firewall, router, and wireless security testing • Privilege escalation and misconfiguration analysis • Login, session management, password reset, and brute-force testing • OWASP Top 10 assessment for the authentication module • Detailed risk analysis with CVSS scoring and PoC evidence Deliverables • Pre-engagement testing plan for approval • Comprehensive PDF penetration test report • Clear remediation recommendations with risk prioritization • Debrief call to review findings (if required) I can start immediately after scope confirmation and NDA execution. Best regards, SHD
₹2,100 INR in 40 days
5.3
5.3

Hi, I am Haresh, having 14+ years of experience in Software Testing Industry. - Having unique blend of knowledge in Quality Product Delivery, Processes Management, Functional testing, Integration and regression testing, load and Perfromance Testing which help me to take the Quality of the software to the next level. - Hands on experience on testing Desktop, Web Based, Mobile application and ERP based application. - Hands on experience on automation testing tools on selenium webdriver, jmeter, katalon studio, Appium, cypress, selenium with TestNG freamwork etc.. - Thorough understanding of Product Delivery Life Cycle, Software Testing Life Cycle and Software Development Life Cycle. - Experience in Well conversant with writing Test plan,Test Cases,Bug report, Release Note and Product Health Report. - Worked in various domains like Finance, Retail, Web Portals, Healthcare, ecommnerce, CMS, Eduction Portal, Life Insurance, ERP system etc. - I do have require mobile devices to test mobile view or applications like android and iOS applications. - I have hands on experience with Git, postman, MSSQL Server. Kindly review my profile and let me know you view over the same. Thanks, Haresh
₹5,500 INR in 40 days
4.8
4.8

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a fully authorized penetration test of your network infrastructure and e-commerce authentication system, following industry-standard methodologies such as PTES, OWASP Web Security Testing Guide, and the OWASP Top 10. Scope * Network Infrastructure: Attack surface mapping, firewall and router configuration review, wireless security assessment, privilege escalation testing, and misconfiguration analysis. * E-commerce Authentication: Login, registration, password reset, session management, brute-force resilience, session fixation, account enumeration, MFA (if applicable), and related authentication security testing. Deliverables * Pre-engagement testing plan for approval * Executive summary and detailed technical report (PDF) * CVSS severity ratings, PoC evidence, and prioritized remediation guidance * Optional remediation validation and debrief session Tools Nmap, Burp Suite Professional, Metasploit, Wireshark, Nessus, Nuclei, OWASP ZAP, and custom validation scripts. Timeline * Reconnaissance: 1–2 days * Security assessment & exploitation: 2–3 days * Reporting: 1–2 days Thanks
₹1,500 INR in 40 days
3.6
3.6

Hiii, ✋ —-->>✦❇️ Audtiting & Testing Expert ❇️✦ <<----- I can conduct an authorized, controlled penetration test covering your network infrastructure and e-commerce authentication flow, with a clear pre-engagement plan and strict scope adherence. I’ll assess attack surface, firewall/router configurations, wireless segmentation, privilege escalation risks, login/session security, brute-force protections, session fixation, password-reset logic, and relevant OWASP risks. Available to start & deliver the best work with 12 yrs of proficiency. -- Regards, Ravi S.
₹5,500 INR in 40 days
3.3
3.3

Hello, I’m interested in assisting with your penetration testing engagement. My background in software quality assurance gives me strong experience validating authentication workflows, identifying security risks, and documenting reproducible findings. I understand the importance of following a clearly defined scope and working only with explicit authorization. My approach includes reviewing the agreed scope, performing structured testing against the approved targets, validating findings manually, assessing their impact, and delivering a professional report with clear reproduction steps, severity ratings (CVSS where applicable), proof-of-concept evidence, and practical remediation recommendations. I maintain clear communication throughout the engagement and can participate in a debrief session to discuss the results. I’m available to start immediately and can provide an estimated timeline once the scope and environment are confirmed. Best regards, Zain Ul Hassan
₹5,500 INR in 40 days
2.6
2.6

Hi, I can help conduct an authorized penetration test covering your network infrastructure and e-commerce authentication flow. I will provide a structured testing plan, perform reconnaissance and vulnerability assessment, validate findings safely, and deliver a detailed report with CVSS ratings, evidence, and remediation guidance. I have experience with OWASP testing, network security assessments, and tools such as Nmap, Burp Suite, Wireshark, and Metasploit.
₹5,500 INR in 40 days
0.0
0.0

Hello, I’m a cybersecurity professional experienced in web application and infrastructure security testing. I can assess your login flow, session management, authentication controls, and network exposure under your written authorization, then provide a professional PDF report with actionable fixes. My approach includes planning, controlled exploitation, documentation, and a final review discussion.
₹5,500 INR in 40 days
0.0
0.0

Hello, I have experience supporting security assessments for web applications and network environments, including vulnerability discovery and remediation guidance. I can prepare a testing plan, execute reconnaissance and validation using industry-standard tools, and deliver a clear penetration testing report. I’m comfortable working under NDA and following strict authorization boundaries.
₹5,500 INR in 40 days
0.0
0.0

Hi, I'd be happy to help with this assessment. I have nearly 8 years of experience in penetration testing and application security, performing security assessments for enterprise environments, including web applications, APIs, and internal/external network infrastructure. For your engagement, I'll first share a testing plan for approval before beginning the assessment. I'll then perform a manual-led penetration test of your network infrastructure and the login/authentication flow of your e-commerce application using tools such as Nmap, Burp Suite, Metasploit, Wireshark, and other industry-standard tools. The assessment will cover attack surface discovery, firewall and network misconfigurations, privilege escalation opportunities, brute-force protection, session management, password reset, user enumeration, authentication bypass, and other OWASP Top 10 risks within the agreed scope. You'll receive a professional PDF report with CVSS scores, proof of concept for confirmed findings, and practical remediation recommendations. I'm also happy to schedule a debrief call to walk through the results. My certifications include CEH, PNPT, AWS Certified Cloud Practitioner, and Certified LLM Security Professional (CLLMSP). Estimated timeline: Reconnaissance & Planning: 0.5 day Testing & Validation: 1–2 days Reporting: 0.5 day I look forward to discussing your requirements. Parthsarthi Biswal
₹8,000 INR in 35 days
0.0
0.0

Hello Sir/Ma'am, I’m interested in assisting with your authorized penetration testing engagement. I have hands-on experience in web application security testing, network reconnaissance, vulnerability assessment, and reporting using tools such as Nmap, Burp Suite, Wireshark, Metasploit, Nikto, and OWASP testing methodologies. I will provide a pre-engagement testing plan, conduct the assessment within the agreed scope, and deliver a detailed report with CVSS scores, proof-of-concept evidence, risk ratings, and actionable remediation recommendations. I’m also comfortable signing an NDA and maintaining complete confidentiality. Before we begin, I have a few questions: • Is the e-commerce application running in a production or staging environment? • Are there any IP ranges, URLs, or systems that should be excluded from testing? • Do you have a preferred testing window to avoid impacting business operations? I look forward to discussing your requirements and delivering a professional, actionable security assessment. Thank you for your time and consideration.
₹1,500 INR in 10 days
0.0
0.0

Hello, I can perform an authorized penetration test of your network infrastructure and e-commerce login system. I am an EC-Council LPT Master and CPENT certified penetration tester with experience in Web, API and Network Security. I use industry-standard tools including Burp Suite, Nmap, Metasploit and Wireshark. You'll receive: Pre-engagement testing plan Detailed PDF report with CVSS scores, PoC and remediation Optional debrief session Estimated timeline: 4–5 days. I'm ready to start immediately after scope confirmation and NDA signing. Thank you.
₹2,500 INR in 40 days
0.0
0.0

Greetings, I am a penetration testing professional with over seven years of experience in the field. My professional details are provided below: Certifications: Peneteation testing expert, ethical hacking, Cyber Law Recent projects: Airline Company, Ecommerce site, europian medical database, etc
₹3,500 INR in 40 days
0.0
0.0

Explicit written authorization, clear scope, and out-of-scope boundaries already defined — that's the kind of engagement brief that makes a pentest actually useful instead of a box-ticking exercise. Splitting network infrastructure from the login/session layer of your e-commerce site is the right call: two very different attack surfaces, two different methodologies. For the network side, I'd start with passive and active recon to map the real attack surface (not just what's documented), then move into firewall/router/wireless probing and privilege escalation attempts once foothold is gained — always inside the agreed rules of engagement. For the login flow, the focus would be exactly where real breaches happen: brute-force and rate-limiting resistance, session fixation/hijacking, password-reset logic flaws, and the relevant OWASP Top-10 checks, with proof-of-concept evidence for anything confirmed exploitable rather than just theoretical findings. I come from a full-stack development background, which is an advantage here — I read authentication and session-handling code the way the person who built it would, so findings come with a clear understanding of why the flaw exists and how to fix it, not just that it exists. Could you share a rough idea of your preferred testing window (business hours vs. after-hours for the network segment), so I can shape the pre-engagement plan around it? Mattia Garreffa — MDB Tech Solutions
₹4,300 INR in 40 days
0.0
0.0

Hello, Instead of a generic template, I analyzed your exact requirements. As the Rank #1 Cyber Security Practitioner in Bangladesh on TryHackMe (Top 5% Globally), I specialize in your target scope. How I will solve your security problems: 1. Network Infrastructure: • Firewall Probing: Test if firewalls can be bypassed using packet crafting. • Privilege Escalation: Simulate how attackers escalate privileges to network admin. • Attack Surface Mapping: Complete exposure check using Nmap and Wireshark. 2. E-commerce Auth & Login Flaws: • Brute-Force Resistance: Test login forms against automated dictionary attacks. • Session Fixation: Inspect tokens using Burp Suite to ensure proper regeneration. • Password-Reset Flaws: Audit the flow for token predictability or manipulation. Why Me? • 3rd Place Winner in National Cyber Security Olympiad (Dhaka University). • I build custom Python/Bash automation tools to find complex logic flaws. • Offering a low rate of ₹1,000/hr to build my history on this platform. Deliverables: • Pre-engagement testing plan for your sign-off. • Comprehensive PDF report with CVSS v3 scores, PoC screenshots, and remediation steps. • Free post-remediation retest to verify your fixes. I am ready to sign the NDA immediately and await your explicit written authorization before scanning. Best regards, Jubed Mia Junior Penetration Tester
₹1,000 INR in 20 days
0.0
0.0

Hello, I can perform a controlled penetration test of your network infrastructure and e-commerce authentication system after receiving your written authorization and am happy to sign an NDA. My approach begins with a pre-engagement plan outlining the scope, testing methodology, and rules of engagement for your approval. For the network assessment, I will map the attack surface, enumerate hosts and services, review firewall and router configurations, assess wireless security (if applicable), identify misconfigurations, and perform controlled privilege escalation where permitted. For the e-commerce application, I will focus on the login and session management mechanisms, testing for brute-force resistance, account lockout, session fixation, session hijacking, password reset weaknesses, insecure cookie settings, authentication bypass, authorization flaws, and relevant OWASP Top 10 vulnerabilities. Payment processing and database layers will remain out of scope unless later authorized. Estimated timeline: • Reconnaissance & Planning: 1 day • Testing: 2–3 days • Reporting: 1 day I look forward to helping strengthen your security posture with a thorough, well-documented assessment.
₹5,500 INR in 40 days
0.0
0.0

As you have written that you need someone who knows OWASP Top 10 and can make good reports, that's me. I aslo have hands on experience in VAPT.
₹5,500 INR in 40 days
0.0
0.0

Hello, I am interested in handling your authorized penetration testing engagement. I hold NPT, WAPT, and CEH certifications, with training focused on network and web application penetration testing. My approach includes structured reconnaissance, vulnerability assessment, authentication and session security testing, controlled exploitation/validation, and professional reporting with CVSS scoring and clear remediation recommendations. For this engagement, I estimate approximately 25–35 working hours, depending on the final number of in-scope hosts, network segments, and authentication flows. Before active testing, I can provide a pre-engagement testing plan for your approval and will work strictly within the agreed scope and written authorization. I am comfortable signing an NDA and will provide a detailed final report containing findings, supporting evidence, severity ratings, and actionable remediation steps. I am available to start once the scope and schedule are confirmed. Thank you for considering my proposal.
₹2,000 INR in 30 days
0.0
0.0

Hello, Your project aligns well with my cybersecurity skill set. I specialize in authorized penetration testing and vulnerability assessment, with a strong focus on identifying real security risks and providing practical remediation. I can perform a structured assessment of your network infrastructure and e-commerce authentication flow within the approved scope. My testing approach follows industry best practices and the OWASP Top 10 methodology while using professional tools such as Kali Linux, Nmap, Burp Suite, Wireshark, Metasploit, and Nikto. What you'll receive: Pre-engagement testing plan for approval Comprehensive penetration testing of the approved scope Professional PDF report with CVSS severity ratings, proof-of-concept evidence, and step-by-step remediation recommendations Post-assessment discussion to explain the findings if required Estimated Timeline: • Reconnaissance: 1 day * Security Testing: 2–3 days * Final Report: 1 day I understand the importance of confidentiality and I'm happy to work under an NDA. I look forward to discussing your requirements and delivering a professional security assessment. Best Regards, Shahzad Ahmad Cybersecurity Analyst | Penetration Testing | Vulnerability Assessment
₹5,500 INR in 40 days
0.0
0.0

Bhopal, India
Member since May 7, 2026
₹12500-37500 INR
₹12500-37500 INR
₹100-400 INR / hour
₹1500-12500 INR
$10-30 USD
$2-8 USD / hour
₹1500-12500 INR
$30-90 USD
$30-250 USD
$10-30 USD
$15-25 CAD / hour
$250-750 USD
₹12500-37500 INR
₹1500-12500 INR
₹3500-4000 INR / hour
£250-750 GBP
$250-750 USD
$250-750 USD
$3000-5000 USD
₹300-3500 INR / hour
₹600-1500 INR
₹1500-12500 INR