Budget: 18000 UAH Deadline: 7 days
Good day.
We can conduct an audit of the web application before the release and prepare a report for the developer - with a description of risks, reproduction steps, priority for fixes, and recommendations for closing vulnerabilities.
Based on experience - we work with corporate systems, personal accounts, roles, payments, integrations, admin panels, and products where an error in access or logic can cost money and reputation. In security, it is important not only to check for typical vulnerabilities but also to assess the application logic - who can see, change, export, pay, delete, and bypass what.
Similar projects with a comparable level of responsibility:
> https://business.ingello.com/platforma - corporate platform with roles, processes, and complex logic
> https://business.ingello.com/forma-crm - CRM where access, client data, and process stability are crucial
> https://systems-fl.ingello.com - our profile in system development and technical expertise
I suggest proceeding with a short technical audit format - we check the application as an external user and as an authorized user with different roles, separately examining the API, forms, sessions, file uploads, access rights, main scenarios, and possible bypasses.
From you, I need a link to the test or release environment, test accounts by roles, a brief description of critical scenarios, and a list of what you are particularly afraid of breaking before the release.
Please clarify:
> are there separate user roles and an admin panel
> do we need to check only the web interface or also the API
The basic estimate is 18,000 UAH and up to 7 days. If the application is large, with payments, accounts, roles, and a large API, after reviewing the links, I will suggest breaking the audit into stages. Note, there is a nuance - a good audit before release should not only find holes but also provide the developer with a clear list of actions; otherwise, it becomes a security theater =/