Perform security / resilience testing of the API and GUI against attack and intrusion techniques.

Employer
no avatar
Piotr Pobikrowski
Description

Required:

1. Having experience in performing security testing, proof of references will be an advantage.

2. possession of at least OSCP certification

3. possession of a higher certification, e.g. eWPT, CREST CRT/CCT, CPTC will be an advantage

4. able to provide a sample report or the scope of information I will be in the report.

5. availability in late March, early April.

API and GUI testing to be done on:

1. SQL Injection.

2. Broken Authentication and Session Management.

3. Insecure Direct Object References.

4. Security Misconfiguration.

5. Sensitive Data Exposure.

6. Missing Function Level Access Control.

7. Cross-Site Request Forgery.

8. Using Components with Known Vulnerabilities.

9. Unvalidated Redirects and Forwards.

10. Penetration of non-public server resources.

Task Order Products:

1. A professional report describing the scope of the tests performed, the areas that passed, the vulnerabilities found, and recommendations on what needs to be corrected.

2. The advantage of the offer will be an additional list of test scenarios for documentation needs.

more to be discussed.

Published
on 2023-03-10

Offers sent (1)

Budget
Negotiable
Copyright
-
Expires in
30 days