
In Progress
Posted
Paid on delivery
Before you bid, please check our "Client profile" on Freelancer.com We are an established employer. Quick and correct work will earn you positive feedback and timely payment. ************************************************************************************************** Project description : Manual Web Application Penetration Tester Needed We are looking for an experienced penetration tester to perform a manual VAPT on a production web application. The testing CANNOT be automated or run via an AI script. It CANNOT be outsourced via code. Please do not waste your valuable time trying to do either. Scope: Public website and authenticated user portal Manual testing following OWASP methodology Limited use of automated scanners for verification only Test for authentication, authorization, business logic, injection, XSS, CSRF, file uploads, API security, and common web vulnerabilities Provide a detailed report with severity ratings, proof of concept, remediation guidance, and one retest after fixes Please include: Relevant experience Your certifications (Examples: OSCP, OSWE, eWPT or equivalent.) Sample redacted report Estimated duration and fixed-price quote What we are looking for - Your ideal skills and experience: - Strong web testing skills - Excellent attention to detail - Ability to work efficiently and meet strict deadlines - Thorough and complete effort - Knowledge of website testing and validation techniques Your VAPT report should include Authentication and session management Authorization and privilege escalation Business logic flaws SQL Injection Cross-Site Scripting (XSS) Cross-Site Request Forgery (CSRF) File upload vulnerabilities API security Security headers Sensitive information disclosure Misconfigurations Deliverables: Your final report should include: Executive summary Technical findings Risk ratings Proof of concept Remediation recommendations Note: Only freelancers with relevant qualifications in VAPT testing should apply. Accuracy and efficiency are crucial for this project. ******************************************************************************************************* Please bid only if you have previous experience and can deliver within the time specified, otherwise do not waste your valuable bid. Work must be 100% clean and professional Timely, sincere work will earn positive feedback and prompt payment. So take the task seriously, and show us your best work. Best of luck in your bid!
Project ID: 40561295
30 proposals
Remote project
Active 6 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

Hello. Approximately how many authenticated user roles are available? Is API documentation (Swagger/Postman) available? Are there any IP restrictions or testing windows for the production environment?
$150 AUD in 2 days
1.8
1.8
30 freelancers are bidding on average $191 AUD for this job

Hello, I reviewed your requirements and appreciate the emphasis on professional, manual testing. My background is primarily in Software QA with 6+ years of experience in functional, regression, API, and web application testing, and I have experience identifying security-related issues during QA activities. That said, I do not hold certifications such as OSCP, OSWE, or eWPT, and I don’t claim expertise as a dedicated penetration tester. Rather than overstate my qualifications, I want to be transparent. If you’re open to a QA-focused security review covering authentication, authorization, session management, input validation, and common web security checks alongside functional testing, I’d be happy to assist. However, if you specifically require a certified penetration tester to perform a full manual OWASP-based VAPT with exploit validation and a formal penetration testing report, I wouldn’t be the right fit. Thank you for your consideration, and I wish you success with your project. Best regards, Zain Ul Hassan
$200 AUD in 7 days
4.9
4.9

Hello, I'm Rudra Kumar and I believe I am the perfect fit for your VAPT testing project. With over 7 years of experience as a QA and DevOps Engineer, I have honed my skills in manual testing, automation testing, performance testing, security testing, and DevOps. My focus has always been on ensuring secure and high-performing applications - exactly what you need for this task. I have demonstrated expertise in implementing pen-testing methodologies, following OWASP guidelines meticulously. My profound knowledge of web application vulnerabilities such as authentication, authorization, injection, XSS, CSRF, API security, among others will aid in comprehensive testing while severely limiting automated scanning tools. I have not only conducted numerous vulnerability assessments but also compiled detailed reports that include severity ratings, proof of concepts, remediation guidance, and more importantly risk ratings and recommended solutions. This enables businesses to improve their software quality by fixing identified vulnerabilities efficiently and effectively. Allow me to bring my passion for quality to safeguard your web application through thorough security validation while delivering timely reports to ensure prompt mitigation efforts.
$150 AUD in 2 days
4.8
4.8

As an experienced penetration tester with over 7 years of experience under my belt, I am well equipped to handle the VAPT needs of your production web application. My approach is different from a checkbox auditor as I think like an attacker to ensure that all possible security gaps are identified before they are taken advantage of. The fact that you are looking for a manual testing process resonates well with my methodology as I place immense emphasis on a thorough and complete effort in line with OWASP methodology. I look forward to the opportunity of collaborating with you on this vital project.
$1,500 AUD in 7 days
4.2
4.2

I have over 3 years of experience in Web Application Penetration Testing and VAPT, performing manual security assessments against production applications following the OWASP Testing Guide and OWASP Top 10. I understand that this project requires genuine manual testing, not automated scans, and that is exactly how I work. My assessment will cover authentication, authorization, session management, business logic flaws, SQL Injection, XSS, CSRF, file upload vulnerabilities, API security, security misconfigurations, sensitive data exposure, and privilege escalation. Automated tools will only be used to validate findings where appropriate, while all vulnerabilities will be manually verified to eliminate false positives. You will receive a professional report containing: * Executive Summary * Technical Findings with CVSS Severity Ratings * Proof of Concept (PoC) * Screenshots and Reproduction Steps * Remediation Recommendations * One complimentary retest after fixes I have experience with Burp Suite Professional, OWASP ZAP, Nmap, and manual exploitation techniques. I can also share a redacted sample VAPT report upon request. I can begin immediately and deliver a thorough, accurate assessment within your required timeline. I am committed to producing a clean, professional report with clear communication throughout the engagement. I look forward to working with you.
$200 AUD in 2 days
2.4
2.4

Hello, I am available to start immediately. I have experience in web application testing, identifying security issues, and preparing detailed reports with clear findings and recommendations. I follow a structured testing approach and pay close attention to detail to ensure accurate, professional results. I can provide well-documented reports with severity ratings, proof of concept, and remediation guidance, along with a retest after fixes if required. I am committed to timely communication, meeting deadlines, and delivering high-quality work. I would be happy to discuss your scope and timeline further and get started right away.
$50 AUD in 1 day
2.0
2.0

Hi there, I'm Rasel Ahmed, Founder of Cyber Shadow. I specialize in manual web application security testing following OWASP methodology. I have read your project description carefully. I understand you need manual penetration testing, not automated scans, not AI-generated reports. That is exactly how I work. My Experience: I have conducted 60+ manual web application penetration tests for clients across e-commerce, SaaS, healthcare, and logistics. I manually verify every finding, no false positives, no automated noise. Certifications: OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) eWPT (eLearnSecurity Web Application Penetration Tester) CEH Master What I Will Test: Authentication and session management Authorization and privilege escalation Business logic flaws SQL Injection, XSS, CSRF File upload vulnerabilities API security Security headers Sensitive information disclosure Misconfigurations Deliverables: Executive summary for stakeholders Technical findings with severity ratings (CVSS) Proof-of-concept for each vulnerability Clear, actionable remediation guidance One retest after fixes are applied Sample Report: I can share a redacted sample report from a previous web application pentest upon request. Estimated Timeline: 7–10 business days (depending on application size) Ready to start immediately. Let me know your timeline and I'll confirm availability. Best regards, Rasel Ahmed Founder, Cyber Shadow
$200 AUD in 7 days
1.7
1.7

Greetings, I see you're looking for a skilled manual penetration tester to perform a VAPT on your web application. My approach would involve thorough manual testing of both the public website and authenticated user portal, following the OWASP methodology closely. I understand the importance of checking for various vulnerabilities, including authentication flaws, SQL injection, and XSS, while providing a detailed report that includes severity ratings and remediation guidance. With my extensive experience in web application security testing and certifications in the field, I'm confident in delivering a comprehensive assessment that meets your requirements. My focus on detail and efficiency ensures that I can identify issues effectively and provide actionable insights. Looking forward to the opportunity to work with you. Best regards, Saba Ehsan
$150 AUD in 3 days
0.5
0.5

Hey , I am skilled content writer with skills including Software Performance Testing, Web Testing, Penetration Testing, Website Testing, Risk Assessment, Usability Testing, Quality and Reliability Testing, Testing / QA, Debugging and Software Testing. "Client profile" Please send a message to discuss more about this project. Your Sincerely
$30 AUD in 2 days
1.2
1.2

As an extensively experienced full-stack developer, my specialty aligns perfectly with your need for manual web application penetration testing. I am well-versed in the OWASP methodology and understand the limitations of solely relying on automated scripts. Manual testing is crucial to uncovering vulnerabilities that tools might miss. Maintaining strict adherence to deadlines while delivering quality results is what I thrive on - a potent combination that ensures satisfactory performance, free from any shortcomings. My commercial experience spans more than 5 years in web development and security, making me adept at identifying and addressing concerns through detailed and comprehensive effort. I hold several certifications, such as OSCP, OSWE, eWPT or equivalent, which are solid endorsements of my capabilities in VAPT testing. Providing you with a sample redacted report demonstrating my previous work is not a problem. You can expect my VAPT report to encompass all the vital aspects like authentication management, authorization and privilege escalation, XSS, CSRF, file uploads, API security, security headers and much more. My final report will feature a concise executive summary along with technical findings, detailed risk ratings backed up by proof of concept documentation as well as remediation recommendations.
$200 AUD in 4 days
0.0
0.0

As an experienced and versatile web developer with a deep understanding of various technologies, I believe I am the perfect fit for your manual VAPT testing project. My lengthy 11-year experience entails a proven track record of incorporating security elements into applications using intricate languages like JavaScript, jQuery, MongoDB, PHP, React, SharePoint, C#, and SQL. This knowledge ensures I can navigate the complex intricacies of a production web application proficiently. Besides being in the field for over a decade, my prolific skills as a website tester offer an excellent blend of accuracy, efficiency and unwavering attention to detail; crucial factors for a manual VAPT test. I am well-versed with OWASP methodology, authenticated user portals, injection, XSS, CSRF, API security and the exhaustive list you provided. What sets me apart is my ability to seamlessly integrate my technical findings to generate detailed reports with precise risk ratings and proof of concept while giving meaningful remediation recommendations. Meticulousness is what I bring to the table. Please look at my portfolio https://www.freelancer.com/u/Firasatw If my work aligns with you then we can discuss further to discuss milestones and deliverables. Regards, Firasat W
$100 AUD in 5 days
0.0
0.0

With an expert in the realm of web application penetration testing like myself, you'll get nothing short of exceptional service that adheres strictly to your unique requirements. My extensive knowledge and experience include conducting manual VAPT following OWASP methodology, utilizing automated scanners for verification only, and testing for a broad range of critical vulnerabilities such as authentication, authorization, business logic flaws, injection, XSS, CSRF, file uploads, API security, and common web vulnerabilities. I hold several relevant certifications including OSCP and OSWE that validate my expertise in vulnerability assessment and penetration testing. To give you an idea of my meticulousness in report creation, I'd be happy to share a sample redacted report fittingly. My estimated duration and fixed-price quote will reflect the comprehensive nature of my work.
$140 AUD in 1 day
0.0
0.0

I have 11 experience automation and manual testing working on domain like hrm e-commerce healhcare eductaion domain and dedicaten 4 hours per day to deliver work on any shift
$140 AUD in 7 days
0.0
0.0

We are ClouSYS Technologies, a growing IT consulting and software development company with extensive experience in delivering high-quality web development, software testing, and QA solutions. Our team has successfully completed multiple projects for clients across various industries, consistently delivering reliable, scalable, and business-focused solutions. ClouSYS Technologies delivers AI, Generative AI, Agentic AI, Cloud, Salesforce, Python, and digital engineering solutions that help businesses innovate, automate, and scale with secure, intelligent, and future-ready technology. We are confident in our ability to deliver a solution that meets your requirements with a strong focus on quality, accuracy, and timely delivery. We have a few questions regarding your project and would appreciate the opportunity to discuss your requirements in more detail. Let's connect for a quick chat to discuss the project and determine the best approach. Thank you for your time and consideration. Best Regards, ClouSYS Technologies AI • Cloud • Innovation
$140 AUD in 7 days
0.0
0.0

Hello, I have a strong background in Software Engineering with hands on experience in secure web application development using Python, FastAPI, REST APIs, authentication systems, and MySQL. I am familiar with the OWASP Top 10, web security testing methodologies, and common vulnerabilities such as SQL Injection, XSS, CSRF, broken authentication, and security misconfigurations. I pay close attention to detail and produce clear, well documented reports with practical remediation recommendations. I am committed to delivering professional, accurate work within the agreed timeline and maintaining clear communication throughout the project. I would appreciate the opportunity to discuss your requirements further.
$140 AUD in 7 days
0.0
0.0

Hi, I've read your requirements carefully, and I understand that you're looking for a genuine **manual** web application penetration test—not an automated scan with a generated report. My approach is to perform a structured assessment following the OWASP Web Security Testing Guide, manually validating authentication, authorization, business logic, session management, injection flaws, XSS, CSRF, file uploads, API security, security headers, sensitive data exposure, and server misconfigurations. Automated tools, where used, would only supplement manual verification to confirm findings. The final deliverable will include an executive summary, detailed technical findings with CVSS/severity ratings, proof-of-concept evidence, remediation recommendations, and one verification retest after fixes. Throughout the engagement, I will maintain clear communication, responsible testing practices, and minimize any impact on your production environment. One question: do you have a defined testing window and an approved scope (domains, APIs, and user roles), or should that be established before the assessment begins?
$120 AUD in 5 days
0.0
0.0

Hi, I've reviewed your scope and this clearly needs genuine manual testing across auth, business logic, and API layers rather than scanner output — that's exactly how I approach engagements. Background: I hold eCPPTv3, eJPTv2, and CNSP certifications, plus CTI 101 and an API Penetration Testing cert. I recently worked as a penetration tester at Commtel on banking and financial infrastructure assessments, so I'm well-versed in the rigor production financial apps demand — session handling, privilege escalation, and business logic abuse especially. I'm also ranked Top 25 in Pakistan on Hack The Box. My approach follows OWASP WSTG phases: mapping the app and auth flows, then manual testing for authN/authZ flaws, injection, XSS, CSRF, file upload issues, and API-specific vulnerabilities (BOLA, mass assignment, etc.), using scanners only to cross-check coverage. Quick question: is MFA in scope for authentication testing, and is there an existing responsible disclosure policy I should align with? Deliverable: full report (executive summary, findings with severity ratings, PoC, remediation) plus one retest post-fix, within 2-3 days for thorough manual coverage. Happy to share a redacted sample report structure on request.
$150 AUD in 2 days
0.0
0.0

Hello, I am a Cyber Security Analyst with 4+ years of experience in Web Application and API Vulnerability Assessment & Penetration Testing (VAPT). I perform manual security testing following the OWASP Testing Guide and use automated tools only to verify findings. I will assess authentication, authorization, business logic, SQL Injection, XSS, CSRF, file upload security, API security, security headers, sensitive information disclosure, and common web vulnerabilities. You will receive a professional report containing an executive summary, detailed technical findings, severity ratings, proof of concept, and practical remediation recommendations. I also provide one retest after the fixes are implemented. I am committed to delivering accurate, confidential, and high-quality work within the agreed timeline. I look forward to working with you. Thank you.
$100 AUD in 7 days
0.0
0.0

OVERWHELMED With all the Ai Generated proposals. Give me a few seconds to show you why I am different. I've performed manual VAPT tests on various web applications, ensuring thorough security checks following OWASP methodology. Understanding the importance of accurate testing and detailed reporting, I aim to provide value through my experience and certifications. I would love to chat about your project, the worst that can happen is you walk away with a free consultation. Regards, Clinton.
$100 AUD in 7 days
0.0
0.0

Hello I see you need a fully manual VAPT of your public site and authenticated portal using OWASP methods I have done manual penetration tests for SaaS and e‑commerce apps and provided reports with severity ratings and remediation advice My approach: Step 1 map the application manually Step 2 test auth session business logic injection XSS CSRF file upload and API endpoints with manual techniques and limited scanner verification Step 3 deliver executive summary technical findings proof of concept and remediation then retest after fixes If this fits let’s discuss timeline and fixed price Thank you for the opportunity
$140 AUD in 2 days
0.0
0.0

⚡ I HANDLE THIS TYPE OF WORK REALLY WELL. I have just completed a manual VAPT on a production web application, following the OWASP methodology for a similar project. The main result you want is a detailed VAPT report with severity ratings, proof of concept, and remediation guidance. I will focus on manual testing, following the OWASP methodology, and providing a detailed report with severity ratings and proof of concept. Two specific technical details from the brief are limited use of automated scanners for verification only and testing for common web vulnerabilities. I will keep everything clear and simple, without burying you in technical nonsense. MESSAGE ME, I WILL KEEP THIS SIMPLE. Regards, Stefan.
$150 AUD in 14 days
0.0
0.0

TAKAPUNA, New Zealand
Payment method verified
Member since Sep 10, 2013
$10-30 AUD
$10-30 AUD
$30-250 AUD
$10-30 AUD
$10-30 USD
₹600-1500 INR
$10-30 USD
$250-750 USD
$20000-50000 USD
₹12500-37500 INR
$25-50 USD / hour
$25-50 AUD / hour
$10-30 USD
₹100-400 INR / hour
$10-30 USD
$30-250 AUD
$30-250 USD
₹12500-37500 INR
$250-750 USD
₹37500-75000 INR
$10-15 USD
£250-750 GBP
₹100-400 INR / hour
₹12500-37500 INR
€18-36 EUR / hour