
Abgesagt
Veröffentlicht
Bezahlt bei Lieferung
I have an existing web application that must be pulled apart and inspected from every angle so we can see exactly where it breaks. The assignment centres on software-level reverse engineering, with the single overriding goal of identifying security vulnerabilities in the code base and its runtime behaviour. Once we confirm your availability I will provide the full application bundle, test server images and any credentials you might need. Your analysis should combine static code inspection with dynamic testing: think Burp Suite for traffic interception, Wireshark or similar packet capture, plus any de-obfuscation or disassembly tools (IDA Pro, Ghidra, etc.) that help you drill into compiled assets. Please follow OWASP guidelines so results are mapped to familiar risk categories. Deliverables • A structured report that lists each vulnerability, severity ranked (CVSS), root-cause explanation and clear remediation steps. • An annotated code map highlighting the vulnerable routines or modules. • Proof-of-concept exploits that reliably reproduce the issues in our staging environment. • A brief walkthrough session (video call or recorded demo) to hand over findings and answer clarifying questions. I plan to break the payment into milestones—reconnaissance results, mid-project draft findings, and final signed-off report—so both sides stay aligned with the scope that supports the agreed ₹2,00,000 total. Everything shared is confidential; an NDA will be required before any source or environment details are released. Let me know your earliest start date and estimated timeline for completion so we can lock in the schedule and move forward.
Projekt-ID: 40444545
17 Vorschläge
Remote Projekt
Aktiv vor 2 Monaten
Legen Sie Ihr Budget und Ihren Zeitrahmen fest
Für Ihre Arbeit bezahlt werden
Skizzieren Sie Ihren Vorschlag
Sie können sich kostenlos anmelden und auf Aufträge bieten
17 Freelancer bieten im Durchschnitt ₹114.604 INR für diesen Auftrag

I can help with this, I will deliver a full vulnerability assessment — static code inspection, dynamic testing via Burp Suite and Wireshark, and binary analysis using Ghidra — with all findings mapped to OWASP categories and scored by CVSS severity. The final package will include the structured report, annotated code map, and working proof-of-concept exploits for your staging environment. One thing I will prioritize early: mapping authentication and session handling flows before broader fuzzing. Broken auth is often the highest-impact finding, and understanding token lifecycle first shapes where deeper analysis pays off. Questions: 1) What is the primary tech stack — interpreted (Python/Node) or compiled assets requiring disassembly? Ready to start whenever you are. Kamran
₹83.767 INR in 25 Tagen
6,0
6,0

With over 7 years of hands-on experience in breaking and securing systems, I believe I am the ideal candidate to undertake your web application vulnerability challenge. Throughout my career, I have successfully provided comprehensive web and API penetration testing services for numerous clients. I am a certified CEH, OSCP, CISSP holder amongst others, and my approach stands out in terms of identifying security gaps that traditional checkbox audits miss. My methodology centers around thinking like an attacker rather than adhering strictly to predetermined guidelines. This approach helps me tackle the vulnerabilities that matter, as evidenced by the critical zero-days I have discovered for clients in the past. In line with your project's scope, my testing will be rooted in OWASP guidelines and will include an amalgamation of static code inspection, dynamic testing through tools like Burp Suite and Wireshark, as well as de-obfuscation or disassembly tools to construct a detailed map of issues in your codebase. Confidentiality is guaranteed, and I prioritize aligning milestones with results to ensure transparency throughout the project. As we progress towards completion, I'll deliver a mid-project draft and a detailed walkthrough session (video call or recorded demo) as stipulated in your project description. Let's start on securing your web application today and ensure peace of mind knowing we've bolstered your security wall!
₹150.000 INR in 14 Tagen
4,5
4,5

Hi there, I’ve reviewed your security testing needs and would be glad to assist. With 10+ years of experience in VAPT, vulnerability assessment, and web/app security testing, I help identify and fix critical security flaws before they become threats. You’ll get a detailed report, practical remediation steps, and complete confidentiality — following OWASP and industry best practices. Let’s connect to secure your application the right way! Best, Bhargav Security Specialist | VAPT & AppSec | 10+ Years Experience
₹75.000 INR in 7 Tagen
2,4
2,4

Boss, I can perform a full security-focused reverse engineering audit of your web application and deliver a detailed vulnerability assessment report with CVSS ranking, PoC exploits, annotated code mapping, and remediation guidance. I have experience with Burp Suite, Wireshark, Ghidra, IDA Pro, OWASP testing methodology, and runtime traffic analysis. I can also handle de-obfuscation and compiled asset inspection where required. I can start immediately after NDA signing and initial access delivery. Estimated timeline is around 18–25 days depending on codebase size and infrastructure complexity. I will provide regular progress updates and milestone-based reporting throughout the engagement. Do you already have a preferred tech stack/environment for the staging setup, and will source code access include backend services and deployment configs as well?
₹112.500 INR in 19 Tagen
1,7
1,7

I will surely help perform a detailed security assessment and reverse engineering analysis of your web application with a strong focus on identifying vulnerabilities, attack surfaces, and runtime weaknesses. My approach will combine static code review, dynamic testing, traffic analysis, and OWASP-based security validation using industry-standard tools such as Burp Suite, Wireshark, Ghidra/IDA, and runtime inspection techniques. The final deliverables will include a structured vulnerability report, severity mapping, proof-of-concept findings, remediation guidance, and a walkthrough session for handover. One quick question: what is the primary tech stack/framework used in the application? I’m comfortable signing an NDA and can discuss the timeline, milestones, and assessment workflow further on a quick call.
₹145.500 INR in 7 Tagen
0,0
0,0

Hi, I can perform a full security-focused reverse engineering and vulnerability assessment of your existing web application under NDA and within the agreed milestone structure. My approach will combine: Static code review to identify insecure logic, weak validation, auth/session flaws, hardcoded secrets, unsafe dependencies and vulnerable modules Dynamic testing using Burp Suite, traffic interception and runtime behaviour analysis Packet inspection with Wireshark where needed De-obfuscation/disassembly review for compiled or bundled assets using tools like Ghidra/IDA where applicable OWASP-based vulnerability mapping with CVSS severity scoring Deliverables will include: Structured security report with severity, root cause, impact and remediation Annotated code/module map showing vulnerable routines Safe proof-of-concept reproduction steps for staging Screenshots/evidence for each confirmed issue Final walkthrough session or recorded demo Clear fix recommendations for developers I’m comfortable working with confidential codebases and can follow your NDA, staging-only testing rules and milestone plan: Reconnaissance and initial findings Mid-project draft report Final verified report and handoff Estimated timeline: 2–4 weeks depending on application size, code complexity and number of environments. I can start after NDA completion, access handover and confirmation of scope/testing boundaries.
₹112.500 INR in 7 Tagen
0,0
0,0

As a seasoned Full Stack Developer and a diligent problem-solver, I believe I am well-suited to take on your challenging project. My deep understanding of network security, honed over 14 years in the field, gives me an ideal perspective for tackling your issue head-on. I have extensive experience in the type of reverse engineering that your web app vulnerabilities project demands, having worked with tools such as Burp Suite, Wireshark, and IDA Pro in numerous projects. A standout of my approach is the marriage of static code inspection with dynamic testing that you require—this allows me to leave no stone unturned in uncovering security vulnerabilities and potential attack vectors within code bases. Committed to keeping up with best practices, I will ensure that my findings are mapped to OWASP guidelines and quantify risks based on CVSS metrics. At ₹2,00,000 for the project, I can guarantee you're getting immense value for your money. The milestones allowed will foster clear alignment and transparency throughout the project ensuring we stay focused on delivering results that meet your risk management needs. It would be a pleasure to sign your NDA and get started at your earliest convenience.
₹200.000 INR in 15 Tagen
0,0
0,0

Hi — security auditing and reverse engineering is my core specialty. I've conducted vulnerability assessments on web applications including finding bugs through bug bounty programs. My approach for your web app: 1. Static analysis: Decompile/inspect frontend code, API endpoints, authentication flows 2. Dynamic testing: Intercept traffic with Burp Suite, test OWASP Top 10 (SQLi, XSS, IDOR, auth bypass) 3. Business logic analysis: Test privilege escalation, payment manipulation, session handling 4. API security: Test rate limiting, input validation, JWT/token vulnerabilities 5. Reverse engineering: Ghidra/IDA for compiled assets, de-obfuscation of JS bundles 6. Full report: CVSS-scored findings with PoC exploits and remediation steps Tools: Burp Suite Pro, OWASP ZAP, Ghidra, Wireshark, Python scripts for custom fuzzing, Playwright for automated flow testing. I'm comfortable with NDA and milestone-based payment. Available to start within 24 hours. Can deliver reconnaissance results within the first week.
₹112.500 INR in 7 Tagen
0,0
0,0

Hello, I am a Pentester with experience in web application security testing and vulnerability assessment. I am interested in assisting with your reverse engineering and security analysis project. I am familiar with Kali Linux, Burp Suite, Nmap, and Wireshark for reconnaissance, traffic interception, packet analysis, enumeration, and vulnerability testing. My approach includes both static inspection and dynamic testing while following OWASP-based methodologies. I can identify most common and moderately advanced vulnerabilities, including broken authentication, access control issues, IDORs, insecure APIs, information disclosure, injection flaws, weak configurations, and other OWASP Top 10 risks. For deeper, chained, or heavily obfuscated vulnerabilities, additional time and analysis may be required, but I will do my best to thoroughly inspect the application and identify as many security weaknesses as possible. I can provide: • Structured vulnerability reports • CVSS severity ranking • Root-cause analysis and remediation steps • Proof-of-concept reproduction steps • Walkthrough/demo of findings • Confidential handling under NDA I am comfortable with milestone-based workflows and can start immediately after NDA completion and environment access. Thank you.
₹75.000 INR in 9 Tagen
0,0
0,0

Hello, I’m a cybersecurity-focused developer with experience in web application security testing and reverse engineering. I can perform a full assessment of your application using both static and dynamic analysis to identify real exploitable vulnerabilities. Approach: • Static code review to detect insecure logic, auth/session flaws, and data handling issues • Dynamic testing using Burp Suite for request interception and manipulation • Network traffic analysis with Wireshark to identify sensitive data exposure • Reverse engineering (Ghidra/IDA-style methods if required) for compiled/obfuscated components • OWASP Top 10 methodology for structured vulnerability classification Deliverables: • Detailed vulnerability report with CVSS severity ratings • Root-cause analysis with clear remediation steps • Annotated mapping of vulnerable modules/functions • Reproducible proof-of-concept exploits in staging • Optional walkthrough session for knowledge transfer I prioritize confidentiality, accuracy, and strict adherence to scope and NDA requirements. I can start immediately after access is provided and align with your milestone schedule. Looking forward to working with you.
₹111.500 INR in 7 Tagen
0,0
0,0

Hello, I am very interested in your project involving in-depth security analysis and reverse engineering of your web application. I have experience in web application security testing, penetration testing, and vulnerability assessment following OWASP standards. I use both static and dynamic analysis techniques, including tools such as Burp Suite for traffic interception, Wireshark for network analysis, and Ghidra/IDA Pro for reverse engineering and code inspection. My approach focuses on identifying root causes of vulnerabilities and providing practical, developer-friendly remediation steps. For your project, I will: Perform full static and dynamic security analysis of the application Identify and document vulnerabilities with CVSS severity ratings Map issues to OWASP Top 10 categories Provide proof-of-concept demonstrations in a controlled staging environment Deliver a structured, professional report with clear remediation guidance Highlight vulnerable code areas with detailed explanations Ensure all findings are reproducible and well-documented I can start immediately after NDA approval and access provision. I estimate completing the full analysis within the proposed timeline while maintaining high accuracy and attention to detail. I am comfortable working in milestone-based delivery and will ensure clear communication throughout the project to keep everything aligned with your expectations. Looking forward to working with you.
₹112.500 INR in 7 Tagen
0,0
0,0

Hi there, As a systems architect with deep experience in code-level analysis, I specialize in combining static inspection with dynamic network interception. I am fully equipped to pull apart your web application to identify, map, and exploit runtime vulnerabilities. My Assessment Strategy: Dynamic Analysis (Traffic Interception): I will use Burp Suite Professional to intercept and manipulate REST/GraphQL traffic, probing for logic flaws, broken access control, and injection vectors (OWASP Top 10). I will use Wireshark to analyze TLS handshakes and raw packet transmissions for secure configuration. Static Analysis (Reverse Engineering): Using tools like Ghidra/IDA Pro, I will drill into any compiled assets or heavily obfuscated JavaScript bundles to map the underlying routines and uncover hardcoded secrets or bypass mechanisms. Exploitation & Reporting: I will provide reliable, reproducible Proof-of-Concept (PoC) scripts for your staging environment. The final deliverable will be a structured report mapping findings to CVSS scores, complete with an annotated code map and strict remediation steps. I am ready to sign the NDA and can begin reconnaissance immediately upon receiving the application bundle. Let me know when you are available for a brief alignment call. Best regards, ASHIQUR RAHAMAN MOLLA
₹112.500 INR in 21 Tagen
0,0
0,0

Nagar Kurnool, India
Mitglied seit Aug. 5, 2020
₹37500-75000 INR
₹12500-37500 INR
$250-750 USD
$10-30 AUD
$10-30 AUD
₹1500-12500 INR
£18-36 GBP / Stunde
€8-30 EUR
$10-30 USD
$30-250 AUD
$14-100 NZD
min. $50 USD / Stunde
$10-30 USD
₹400-750 INR / Stunde
$30-250 USD
₹12500-37500 INR
₹12500-37500 INR
₹12500-37500 INR
₹12500-37500 INR
$250-750 USD
$30-250 USD
$10-30 USD