Manual penetration test: multi-tenant authorization and access control (Laravel healthcare SaaS)
Budget: $60.0 - $110.0
HOURLY / PART_TIME
⭐ 4.99 (5)
United States
penetration-testing, vulnerability-assessment, application-security, web-application-security, owasp, laravel-framework
Bevorzugte Qualifikationen
- Erfahrung: Experte
- Englisch: Konversationssicher
- Job Success: 90%+
- Rising Talent bevorzugt
- Mindestverdienst: $10,000+
I need a focused manual penetration test of a multi-tenant healthcare web application before a September launch. This is a targeted authorization-focused engagement, not a full-scope test. I am not looking for automated scanner output.
About the application
Server-rendered Laravel (PHP-FPM) on AWS: CloudFront and WAF, Application Load Balancer, ECS Fargate, RDS MariaDB, S3. No separate REST API. Roughly [X] web routes.
It is a B2B SaaS platform for medical practices. Each practice is a tenant. Every patient record, note, appointment, and invoice belongs to exactly one practice, and no practice should ever see another practice's data. There are seven user roles: patient, provider, medical assistant, practice manager, billing, marketing, and admin.
What I need tested, in priority order
Tenant isolation. Can a user authenticated at Practice A reach any data belonging to Practice B by manipulating IDs in URLs, form parameters, or requests?
Broken object level authorization within a tenant. Can a patient reach another patient's records? Can a lower-privileged role reach records they should not?
Role boundary enforcement across all seven roles, including whether restrictions are enforced server-side or only hidden in the UI.
Authentication and session management: login, MFA, session handling, password reset, account enumeration.
File upload handling. The app accepts CSV and XLSX imports. Please test for formula injection, path traversal, malicious file content, and parser abuse.
Webhook endpoints. Signature verification on inbound webhooks from payment and third-party services.
Environment and access
Grey box, fully authenticated. I will provide credentials for two separate test practices and for every role, against a staging environment configured like production. Staging contains synthetic test data only. No real patient data will be present at any point.
Deliverables required
Findings report with severity ratings (CVSS), reproduction steps, and request and response evidence for each finding
Remediation guidance my developer can act on
One round of retesting after fixes, included
A short call or written summary walking me through the findings
Timeline
Code freeze is August 25. Testing can begin August 26. I need findings by roughly September 1 so there is time to remediate and retest before launch.
Requirements
OSCP, OSWE, or equivalent hands-on certification
Demonstrated manual testing of multi-tenant SaaS authorization, not scanner-based assessments
Willing to sign an NDA
Please include a sanitized sample report or a description of what your report contains
In your proposal, please answer: how do you test tenant isolation specifically, and what do you need from me to do it well?
Auf Upwork öffnen
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Anmelden