Web Login Penetration Test -- 2
Publicada el 2026-07-31
Descripción de la oferta
I run a blog-style content website and need a focused penetration test on its user-login area. The goal is to uncover any weaknesses that could allow unauthorized access through the regular sign-in form. Scope • Target: publicly facing web application (content/blog platform). • Focus: user login security only—credential handling, session management, brute-force protections, and related OWASP Top 10 items. • Excluded for now: password-reset flow and admin control panel, though I may extend testing later. Expectations 1. Perform both automated and manual testing using recognised tools such as Burp Suite, OWASP ZAP, Hydra, or similar. 2. Attempt common password-based attacks (e.g., dictionary, credential stuffing, session fixation) in a controlled manner that will not disrupt normal site availability. 3. Provide a concise report detailing: – Discovered vulnerabilities ranked by severity – Proof-of-concept evidence or logs – Clear remediation recommendations tailored to my CMS/stack Access & Coordination I will grant you a dedicated test account and agree on a limited time window so monitoring teams are aware of the activity. All findings must remain confidential under an NDA. If you have previous experience hardening login systems for content sites, I’d love to see a brief example report or reference.
Skills
Fuente original: freelancer