← WORK 목록으로
GLOBALFreelancer웹 개발REMOTE

Penetration Testing Secure Code Review & Fixing

여러 프리랜서가 이어붙여 만든 프로덕션 사이트의 보안을 진단·개선하는 프로젝트입니다. React·Node.js·MongoDB 코드베이스를 라인 단위로 검토해 OWASP Top 10 취약점을 찾아 직접 패치하고, 침투 테스트로 수정 결과를 검증한 뒤 취약점-패치-재테스트를 매핑한 보고서를 제출해야 합니다. 인증·결제·데이터 저장 보안에 강하고, 정적 분석 도구(Burp Suite, ZAP, SonarQube 등)와 수동 리뷰를 병행할 수 있는 보안 전문 개발자에게 적합합니다.

2026.09.29VIEW 9Freelancer에서 수집
Budget$30~$250 USD
Difficulty전문가
Duration1~2개월
Work style원격 가능
Required stack

필요 기술

ReactNode.jsMongoDBPenetration TestingWeb SecurityOWASPBurp Suite
Project brief

프로젝트 내용

have a production-ready site that was stitched together by several freelancers. While the feature set works, the underlying security clearly does not: I can already spot areas where input is not sanitised and session handling feels weak. I now need a professional who can take the codebase apart, find every vulnerability, patch it, and then prove the fixes hold under pressure.

Here is what I am looking for:
• A full secure-code review of the existing React JS, Node js, and MongoDB line by line where necessary, identifying logic flaws, misconfigurations, and any OWASP Top 10 issues.
• Active penetration testing once the review is complete, so we validate your fixes in a real-world scenario rather than stopping at theoretical findings.
• Clear, developer-ready remediation: update the code yourself, comment the changes, and supply a concise report that maps each vulnerability to its patch and retest results.

The most critical areas—user authentication, payment processing, data storage, and really anything that could be abused—must emerge bullet-proof when you are done. Please show relevant past work (redacted reports or links to resolved CVEs are ideal) so I can see the depth of your experience. If you routinely combine static analysis tools (Burp Suite, OWASP ZAP, SonarQube, etc.) with manual review, mention that as well.

I will grant repository access after NDA. Final acceptance happens only after we rerun penetration tests and everything comes back clean
지원 기회 분석

지원 전에 볼 것

핵심 요구사항

  • React/Node.js/MongoDB 시큐어 코드 리뷰 및 OWASP Top 10 취약점 식별
  • 취약점 직접 패치 및 코드 주석 처리
  • 수정 검증을 위한 실제 침투 테스트 수행
  • 인증·결제·데이터 저장 등 핵심 영역 보안 강화
  • 취약점-패치-재테스트 매핑 보고서 작성
  • NDA 체결 및 관련 과거 실적(리다크션 보고서/CVE) 제시

예상 산출물

  • 시큐어 코드 리뷰 및 취약점 목록
  • 패치가 적용된 코드베이스
  • 침투 테스트 결과 및 재테스트 리포트
  • 취약점-패치 매핑 보고서

매력 포인트

  • 요구 범위와 산출물이 비교적 명확함

확인할 점

  • 예산($30~250)이 전체 코드베이스 보안 감사·패치·침투 테스트 범위에 비해 지나치게 낮음
  • 입찰 145건으로 경쟁 과열, 클라이언트 이력 정보 없음
  • 코드베이스 규모·기간 미명시로 작업량 산정 불가
Client signal

클라이언트 정보

플랫폼에서 상세 정보를 확인하세요.
START THE LOOP · CHOOSE

시장과 사람의 답을 봤다면,
다음 결과물의 구조를 고릅니다.

한 번의 결과에 기대지 않고 다시 만들 수 있도록, 문제 발견부터 제작·배포·수익화까지 이어지는 전체 흐름을 익혀보세요.

TTJ CLASS에서 다음 구조 고르기 →
처리 중...