Login Security Penetration Test - Brute Force attacks

Cliente Freelancer · Remoto · Remoto · freelance · mid · 600–1500 INR

Publicada el 2026-07-22

Descripción de la oferta

I need a thorough ethical hacker to focus exclusively on the login and authentication layer of my live website. Your task is to discover and document any weakness that could let an attacker slip past the sign-in screen—brute-force risks, credential-stuffing avenues, insecure password reset flows, session fixation, you name it. Use whatever industry-standard tooling you prefer (Burp Suite, OWASP ZAP, Kali, custom scripts), combine it with manual probing, and follow OWASP Top 10 practices. Payment pages and general UI aren’t in scope this round, but if things go well I may open that up afterward. Deliverables • Penetration-test report detailing each finding, its risk rating, and clear remediation steps • Proof-of-concept payloads or scripts where a vulnerability can be exploited • Brief retest after fixes to confirm the issues are closed Acceptance criteria: every critical or high-risk issue you uncover must be either fixed or have a documented compensating control, and the follow-up test must show the login path can no longer be breached by the same method. Let’s complete the first pass within one week, with quick daily check-ins so I can track progress.

Skills

Fuente original: freelancer

Análisis JobHunter