Penetration Test: Network & E-Commerce
Publicada el 2026-07-23
Descripción de la oferta
I need a seasoned ethical hacker to run a controlled penetration test on two specific assets I own: 1) my network infrastructure and 2) the user-login / authentication flow of my e-commerce site. You will receive explicit written authorisation before we begin, and I am happy to sign an NDA in return. Scope in brief • Network infrastructure – map the attack surface, probe firewalls, routers and wireless segments, attempt privilege escalation and highlight any misconfigurations. • E-commerce site – focus strictly on the login and session handling mechanisms, checking for issues such as brute-force resistance, session fixation, password-reset flaws and other OWASP Top-10 vulnerabilities. (Payment gateway and database layers are out of scope for now; we can expand later.) Acceptance criteria & deliverables • Pre-engagement testing plan for my sign-off • Penetration-test report (PDF) that includes CVSS scores, proof-of-concept evidence and clear remediation steps • Optional debrief call to walk through findings Kindly include in your proposal: – A brief overview of comparable projects you have completed – Any relevant certifications (OSCP, CEH, CISSP, etc.) – Your estimated timeline and a cost breakdown for reconnaissance, exploitation and reporting phases Familiarity with common toolsets—Nmap, Burp Suite, Metasploit, Wireshark or equivalents—will be assumed. I’m ready to start as soon as we align on scope and schedule.
Skills
Fuente original: freelancer