I will peform penetration testing and vulnerability assessment
Ethical Hacker: Web Pentesting and Security Reports
About this Gig
I will perform a professional website penetration test (ethical hacking) to identify vulnerabilities before attackers exploit them.
What you get:
- Automated scanning + manual testing to find high-impact issues (OWASP Top 10, auth flaws, session issues, IDOR, XSS, SQLi, SSRF, misconfigurations, sensitive data exposure).
- Verified findings with proof-of-concept (PoC) and risk rating (Critical / High / Medium / Low).
- Clear, prioritized remediation steps you can hand to developers.
- Final vulnerability assessment report (PDF) and short executive summary.
Important legal & scope
I will only test systems you own or for which you provide written authorization (domain(s), scope, and allowed testing window). I will not perform testing outside the agreed scope. By ordering, you confirm you have permission to test the target.
FAQ
Do you need permission to test the site?
Yes — I require written authorization from the owner. I cannot ethically or legally test sites without it.
Do you test production?
I can test production only with prior agreement and during a mutually agreed testing window. Note that some tests may affect availability.
Will you provide PoCs?
Yes — I provide proof-of-concepts and evidence for verified findings so your developers can reproduce and fix them.
Do you disclose vulnerabilities publicly?
No. I keep everything confidential. We can discuss coordinated disclosure if desired.
What tools do you use?
I use a mix of automated scanners and manual tools/techniques (Burp Suite, proxying, manual payloads, targeted logic testing). (Tools may vary.)
Is data safe during testing?
I do not exfiltrate or store sensitive user data beyond what’s needed for evidence. If you require a stricter NDA, we can sign one.

