
Fechado
Publicado
Pago na entrega
Project Title: Vulnerability Assessment and Penetration Testing (VAPT) for Web Application Project Description: We are looking for an experienced cybersecurity professional or freelancer to perform Vulnerability Assessment and Penetration Testing (VAPT) on our web application. The goal is to identify and fix security vulnerabilities to improve overall application security. Scope of Work: Complete security testing of the web application Testing of all major modules/pages (screenshots will be provided) Authentication & authorization testing API security testing Input validation and data exposure checks Business logic vulnerability testing OWASP Top 10 vulnerability assessment Manual + automated penetration testing Deliverables: Detailed VAPT Report (with risk levels: Low, Medium, High, Critical) Proof of Concept (PoC) for identified vulnerabilities Clear remediation steps to fix issues Optional re-testing after fixes (if required) Technical Details: Platform: Web Application Backend: NestJS (Node.js) Frontend: (Specify if Angular / React / etc.) Hosting: VPS Server Access: Will be provided (Staging/Production as required) Attachments: Application screenshots (for scope understanding) Timeline: Expected completion within 5–10 working days (flexible) Requirements: Proven experience in VAPT / Ethical Hacking Strong knowledge of OWASP Top 10 Experience with API security testing Ability to clearly explain vulnerabilities and fixes Additional Notes: Certification is NOT required for this project Focus is on identifying vulnerabilities and providing fixes Please share previous work or sample reports if available Note for Freelancer: Please review before quoting. Application [login to view URL] or bat-1,123 access can be shared if required for accurate estimation.
ID do Projeto: 40311366
32 propostas
Projeto remoto
Ativo há 25 dias
Defina seu orçamento e seu prazo
Seja pago pelo seu trabalho
Descreva sua proposta
É grátis para se inscrever e fazer ofertas em trabalhos
32 freelancers estão ofertando em média ₹10.996 INR for esse trabalho

Hi, I can conduct a comprehensive VAPT on your web application with a strong focus on uncovering real-world exploitable vulnerabilities not just automated scan results. I will combine manual testing + advanced tools to assess authentication, API security, business logic flaws, and full coverage of OWASP Top 10, especially in your NestJS backend. You’ll receive a **clear, developer-friendly report** with risk ratings, step-by-step PoC, and precise remediation guidance to fix issues quickly. I’ve handled similar web app and API security assessments and can also support **re-testing after fixes to ensure everything is properly secured. I can start immediately and deliver within your timeline. Let’s secure your application effectively. Best regards, Kajal Majhi
₹30.000 INR em 7 dias
4,9
4,9

I can perform a complete VAPT on your web app, covering OWASP Top 10, API security, authentication flows, and business logic vulnerabilities. I’ll use a mix of manual and automated testing to uncover real, exploitable issues with clear PoC evidence. You’ll receive a detailed report with risk levels and step-by-step remediation guidance for each finding. I can also support re-testing after fixes to ensure your application is secure and production-ready.
₹3.000 INR em 1 dia
3,9
3,9

As the head of a 9-year-old software development company, I can assure you that we possess the necessary skills and experience for your Web Application VAPT project. Our proficiency in Node.js is particularly beneficial as it aligns directly with your backend technology, NestJS. We also have significant knowledge in web and mobile development, with an array of successful projects under our belt. Conducting vulnerability tests and identifying potential risks are tasks that we take seriously. Our tried-and-tested approach includes thorough manual and automated penetration testing that will be on full display for your project. With a comprehensive understanding of OWASP Top Ten vulnerabilities, we ensure no stone is left unturned in making your web application as secure as possible. What sets us apart is our ability to clearly illustrate vulnerabilities and deliver precise remediation steps, alongside a detailed VAPT report when required. Finally, our unwavering promise of free post-delivery support for three months should bring you peace of mind when choosing us for this crucial task. We are eager to help turn your application into a fortified bastion against any security threats it might face.
₹15.000 INR em 7 dias
4,4
4,4

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive VAPT for your web application (NestJS backend). Approach • Full manual + automated testing aligned with OWASP Top 10 • Coverage of authentication, authorization, APIs, input validation, and business logic flaws • Testing using Burp Suite, OWASP ZAP, Nmap, and custom scripts • Safe testing on staging/production without disruption Deliverables • Detailed VAPT report with Low/Medium/High/Critical risk ratings • Proof of Concept (PoC) with screenshots/logs • Step-by-step remediation guidance • Optional retest after fixes Timeline • 5–7 working days depending on scope We have experience securing SaaS, fintech, and web platforms and can start immediately once access is provided. Sample reports can be shared on request.
₹12.500 INR em 7 dias
3,6
3,6

As an experienced cybersecurity professional with a passion for delivering robust VAPT services, I am confident in my capacity to meet and exceed your expectations. My seven years in the field of ethical hacking have allowed me to hone my skills in web, API, cloud, and network attacks - I believe that this knowledge would be greatly suited for your project. Moreover, as a certified CEH, OSCP, PNPT, CISSP, and eWPT professional; I possess comprehensive knowledge of industry-standard methodologies like OWASP Top 10, PTES, MITRE ATT&CK, and OSSTMM. My proficiency with advanced tools such as Invicti, Nessus, Nmap, OpenVAS, and Qualys will enable efficient automated scanning to pinpoint vulnerabilities precisely throughout your web application. Beyond meticulous vulnerability assessment and penetration testing, I've developed expertise in secure code review to eliminate application logic flaws. This allows me to not only identify potential issues but also provide actionable remediation steps that foster safer digital environments
₹100.000 INR em 7 dias
3,2
3,2

Hello, I see you need a thorough VAPT for your web application focusing on identifying and fixing security vulnerabilities. Your emphasis on testing all major modules, including authentication, API security, and business logic, shows your commitment to robust security. You require a detailed assessment covering OWASP Top 10 risks, manual and automated testing, and clear remediation steps. The backend is in NestJS with Node.js, and you’ve mentioned screenshots for scope, which will help in covering all critical pages. Your request for proof of concept and optional retesting aligns with ensuring vulnerabilities are effectively resolved. I have conducted similar VAPT projects on web applications built with Node.js and AngularJS, delivering comprehensive reports with risk classification and PoCs. My work involved API security testing and manual validation of business logic vulnerabilities, ensuring clear, actionable remediation steps were provided to clients. I can complete the assessment and deliver the full report within 7 working days. I’m ready to start as soon as you provide access and look forward to discussing the details further.
₹1.650 INR em 7 dias
2,1
2,1

Hi there! I have carefully reviewed your project for a Vulnerability Assessment and Penetration Testing (VAPT) for your web application. With a strong background in cybersecurity and experience in conducting VAPT assessments, I am confident in my ability to identify and address security vulnerabilities to enhance your application's overall security. I have previously worked on a similar project for a technology startup, where I conducted a comprehensive VAPT assessment on their web application. By conducting both manual and automated testing, I was able to provide a detailed report with risk levels and clear remediation steps to address the identified vulnerabilities effectively. Could you please provide more information on the specific modules/pages of your web application for a more targeted assessment? Additionally, do you have any specific requirements for re-testing after the fixes are implemented? Looking forward to the opportunity to work on this project with you. Thanks, Tejbir Bhatia
₹7.000 INR em 7 dias
0,0
0,0

Hi Brother, I have 5+ years of experience in penetration testing including Web Application penetration testing; System Application penetration testing; Mobile application penetration testing; Network application penetration testing; social engineering penetration testing etc. Follow systematic approach and best industry methodology like OWASP Testing Guide v4(OTGv4) ; SANS top 25; NIST SP 800-115; PCI DSS etc to perform penetration testing : Web Application Testing : Perform both manual and automated penetration testing for vulnerabilities like SQL injection, Cross-site scripting(XSS), Cross-site request Forgery(CSRF), Code injections, Authentication Bypass, Access Violation, Remote File inclusion(RFI),Local File Inclusion(LFI) etc. Network Testing: Provide Network Penetration Testing so that your Network Infrastructure is secured from the real attacks. Perform both manual and automated network penetration testing to identify network security threats in your network. I can assure you that I will be an ideal candidate for what you are looking for. Please out to me for further discussions. Thank you
₹7.000 INR em 7 dias
0,0
0,0

Hello! Monica Bhatia here, I’m interested in this job. I have 5 years of experience in cybersecurity, specializing in Vulnerability Assessment and Penetration Testing (VAPT) for web applications, including Node.js backends and modern frontend frameworks. I intend to perform a comprehensive security assessment of your web application, covering authentication, authorization, API security, input validation, business logic, and OWASP Top 10 vulnerabilities. The work will combine manual and automated testing to identify risks. I will provide a detailed VAPT report with risk levels, proof-of-concept for vulnerabilities, and clear remediation steps. Optional re-testing can be performed to verify fixes. Warm Regards, Monica Bhatia
₹7.000 INR em 7 dias
0,0
0,0

Your NestJS web app needs thorough VAPT testing across all modules plus API endpoints - I'll run both automated scans and manual penetration tests targeting OWASP Top 10 vulnerabilities, authentication bypasses, and business logic flaws. I'll deliver a detailed report with risk classifications and clear remediation steps for each finding. Built similar security-focused projects including a price aggregation engine that handles 800+ endpoints securely and a Telegram operations bot with robust authentication controls. You can see my technical work at ffulb.com. I'll need your application URL and testing credentials to assess the scope properly and deploy custom vulnerability scanners. Can start immediately and deliver the complete VAPT report within your 5-10 day timeline. Once I take a look at your staging environment, I'll confirm the exact testing approach and timeline.
₹3.210 INR em 5 dias
0,0
0,0

You’re looking for a **practical VAPT**, not just a checklist report—and that’s exactly how I approach it. The focus will be on finding *real, exploitable issues* and giving you clear, actionable fixes your dev team can implement quickly. I’ve worked on Node/NestJS-based applications before, so I understand where common gaps appear—especially around **auth flows, API exposure, and business logic flaws**. **How I’ll handle your VAPT:** * Full **OWASP Top 10 assessment** (manual + automated) * Deep testing of **authentication, authorization, and session handling** * **API security testing** (tokens, rate limits, data exposure, improper access) * **Input validation & injection testing** (XSS, SQLi, etc.) * **Business logic testing** (bypasses, privilege escalation, edge cases) * Review of **headers, configs, and server-level risks (VPS)** **Deliverables:** * Detailed VAPT report (Low → Critical classification) * Clear **PoC (screenshots/steps)** for each vulnerability * **Step-by-step remediation guidance** (developer-friendly) * Optional **re-test after fixes** to confirm closure Quick question: is rate-limiting or WAF already configured on your VPS, or should I assess that as part of testing? Happy to review staging access and give you a precise scope before starting. Praveen Sharma
₹1.500 INR em 15 dias
0,0
0,0

Hi, I can perform a full Vulnerability Assessment and Penetration Test (VAPT) on your web application, covering all modules, APIs, authentication and authorization flows, input validation, business logic, and OWASP Top 10 vulnerabilities. The assessment will combine manual and automated testing, producing a detailed report with risk levels, proof-of-concept for identified issues, and clear remediation steps. Optional re-testing can be provided after fixes. For accurate estimation of effort and timeline, I’d like to review the application using the access you can provide (staging or credentials). This ensures a complete and precise VAPT report tailored to your system. Timeline: 5–10 days Budget: ₹12,000 (adjustable based on final review)
₹12.000 INR em 10 dias
0,0
0,0

I am a security researcher with more than 2 years of experience in web application VAPT. I can perform complete security assessment of the web application covering all endpoints and provide detailed vulnerability assessment report covering summary, detailed descriptions of each vulnerability, Business impact, severity with CVSS score, steps to reproduce and poof of concept along with remediation of each vulnerabilities using manual as well as automated tools Covering OWASP top10.
₹7.000 INR em 7 dias
0,0
0,0

Dear [Client Name], I am excited to submit my proposal for the Vulnerability Assessment and Penetration Testing (VAPT) project for your web application. With my extensive experience in Node.js, Express JS, and network security, I am confident in my ability to identify and fix security vulnerabilities to enhance your application's overall security. I have a strong background in VAPT and ethical hacking, along with a deep understanding of OWASP Top 10 vulnerabilities and API security testing. My expertise will allow me to conduct comprehensive security testing, provide detailed reports with risk levels, and offer clear remediation steps to address any issues. I am committed to delivering high-quality results and ensuring the security of your web application. Please feel free to review my previous work and
₹8.000 INR em 3 dias
0,0
0,0

Hello, I'd be happy to help with your project and make sure everything is done properly and reliably. I have experience with both manual and automated security testing, following OWASP Top 10 guidelines to find and fix potential vulnerabilities
₹8.000 INR em 14 dias
0,0
0,0

hello With 13+ years of experience in cybersecurity and web application development, I can perform a thorough Vulnerability Assessment and Penetration Testing (VAPT) on your web application to identify and remediate security risks. • Comprehensive security testing of all modules and APIs (NestJS, Angular/React) • Authentication, authorization, input validation, and business logic checks • Manual + automated testing covering OWASP Top 10 vulnerabilities • Detailed VAPT report with risk levels, PoC for vulnerabilities, and remediation steps • Optional re-testing to verify fixes and ensure robust security Why hire me? I combine deep technical expertise with clear, actionable reporting for secure, resilient applications. Let’s collaborate to fortify your web platform effectively.
₹12.000 INR em 7 dias
0,0
0,0

Hello, I see you are looking for a professional to perform Vulnerability Assessment and Penetration Testing (VAPT) on your web application, focusing on identifying and fixing security vulnerabilities. I am Mubashir Ahmed, a Full-Stack Developer, Engineer, and UI/UX Specialist with over 6 years of experience building high-performance web applications. My expertise includes conducting thorough security audits, penetration testing, and providing clear remediation steps to enhance application security. To address your needs, I will deliver a comprehensive VAPT report detailing risk levels, a Proof of Concept (PoC) for identified vulnerabilities, and clear remediation steps to fix issues. Additionally, I can offer optional re-testing after fixes, if required. - Step 1: Conduct a complete security assessment of the web application, including all major modules. - Step 2: Perform authentication, authorization, and API security testing. - Step 3: Execute manual and automated penetration testing, focusing on OWASP Top 10 vulnerabilities. - Step 4: Compile a detailed VAPT report with risk levels and remediation steps. - Step 5: Provide a PoC for identified vulnerabilities and optional re-testing. My Portfolio: https://www.freelancer.com/u/mubashir021/QA-Security-Engineer I look forward to helping you improve your web application's security. Mubashir Ahmed
₹7.059,01 INR em 7 dias
0,0
0,0

Hello, I have reviewed your project and I can assist you with the cybersecurity and security testing aspects. I specialize in identifying vulnerabilities, analyzing system behavior, and improving overall security posture. For your project, I can: * Perform basic penetration testing and vulnerability assessment * Identify security risks in your application or network * Analyze potential weaknesses and suggest improvements * Provide a clear report with actionable recommendations I focus on the security side and can work alongside your development stack (Node.js / Angular) without any issues. I have hands-on experience in cybersecurity, SOC operations, and threat analysis through practical labs and real-world scenarios. Looking forward to working with you. Best regards, Youseph Fatouh
₹2.000 INR em 3 dias
0,0
0,0

Hi, With 16+ years of experience in cybersecurity and VAPT, I specialize in comprehensive web application penetration testing aligned with OWASP Top 10. I understand you need a full VAPT assessment covering application modules, APIs, authentication, and business logic vulnerabilities with clear remediation steps. For your project, I will: • Perform end-to-end testing of all modules/pages • Test authentication, authorization, and session management • Conduct API security testing and data exposure checks • Identify input validation issues and business logic flaws • Use manual + automated testing (Burp Suite, OWASP ZAP, etc.) Deliverables include a detailed VAPT report with risk levels (Low–Critical), PoCs, screenshots, and step-by-step fixes. I can also provide a retest after remediation. I can complete this within your 5–10 day timeline with clear communication. We can finalize the budget depending on the complexity of the application. Best regards, SaD
₹18.666 INR em 7 dias
1,4
1,4

Hello, I’m a cybersecurity professional from CT-Infosec, experienced in conducting comprehensive VAPT engagements aligned with OWASP Top 10, NIST, and MITRE ATT&CK frameworks. I have hands-on experience in web application, API security testing, and business logic vulnerability assessment. For your project, I will perform both manual and automated testing covering authentication, authorization, input validation, data exposure, and API endpoints. My approach ensures deep vulnerability identification beyond automated scans. Deliverables include: ✔ Detailed VAPT Report (Low to Critical risk classification) ✔ Proof of Concept (PoC) for each vulnerability ✔ Clear and actionable remediation steps ✔ Optional re-testing after fixes I follow a structured methodology: Discovery → Testing → Exploitation → Reporting → Remediation Support, ensuring accurate and practical results. I have prior experience working on similar projects and can share sample reports upon request. My focus is not just finding vulnerabilities but helping you secure your application effectively. Timeline: 5–10 days (as per scope) Looking forward to working with you. Best Regards, Team CT Infosec
₹6.000 INR em 5 dias
0,0
0,0

New Delhi, India
Membro desde mar. 22, 2025
$1500-3000 USD
$250-750 USD
$50000-100000 USD
$2-15 USD / hora
₹600-1500 INR
₹12500-37500 INR
$250-750 USD
₹600-1500 INR
$30-250 USD
$30-250 USD
$15-25 USD / hora
$250-750 USD
₹1500-12500 INR
£250-750 GBP
$25-50 AUD / hora
€30-250 EUR
$10-50 USD
$25-50 USD / hora
$15-25 USD / hora
₹1500-12500 INR