.NET Web App Pen Test
Publicada el 2026-07-28
Descripción de la oferta
I need a focused security review of my existing .NET website. The goal is to carry out a full-scope penetration test limited to the web-application layer so I can understand exactly where the site is vulnerable and how to fix those weak spots. Scope • Only security is in scope—performance and code-quality audits are out of scope for this assignment. • The test must be performed from the perspective of an external attacker interacting with the public-facing site (no network or internal testing). • Standard web-app vectors should be covered: authentication, session management, input validation, authorization, business logic, insecure deserialization, and any other OWASP Top 10 issues relevant to a .NET stack. What I expect to receive 1. A concise executive summary describing overall risk. 2. A technical report that lists each finding with: – risk rating, – reproducible proof of concept (steps or scripts), – clear remediation guidance suited to .NET / ASP.NET MVC. 3. A short debrief call or recorded walkthrough clarifying critical items. Tools & methodology Feel free to use Burp Suite, OWASP ZAP, or your preferred frameworks, provided the approach remains non-destructive and complies with ethical testing standards. Acceptance criteria The engagement is complete once I receive the report, I can reproduce at least one of the provided PoCs, and all critical or high findings come with actionable fixes. If this matches your skill set and you can start soon, let’s move forward.
Skills
Fuente original: freelancer