Find Jobs
Hire Freelancers

Vulnerability Tester

$5000-10000 USD

Ditutup
Dibuat 9 bulan yang lalu

$5000-10000 USD

Dibayar ketika dikirim
DON'T BID IF YOU DON'T FOLLOW THE INSTRUCTIONS, I WILL HIDE YOUR BID AND IGNORE Please read before you apply , you must accomplish the following before applying (DO NOT APPLY IF YOU DON’T HAVE A VULNERABILITY POC FOR THIS PROJECT TO SHOW): 1. Have read all the sections below 2. Have found a vulnerability in the sections below and have found a solution based off the vulnerability list 3. Have written a POC based off the POC guidelines I will message or reply only freelancers that have done this, follow this and we would work long term with a lot of advantages. Also you're don't need to find vulnerabilities in all assets in scope -- you can just find as much as possible, more that are solid - more money. POC 1. POC Guidelines and Rules ([login to view URL] )
 2. POC Templates Article ([login to view URL] ) PROJECT OVERVIEW Your POC should identify vulnerabilities on either the smart contract or app that prevent: Loss of funds Loss of more than 10% of yield Freezing of funds that cannot be undone by admin actions Ability for an unauthorized user to use admin actions Governance process failures Redirected funds by address modification Shell access on server Injection of text Ability to have other users run arbitrary code on the site ASSET IN SCOPE Smart Contract [login to view URL] Target Smart Contract - OUSD Type [login to view URL] Target Smart Contract - Vault Type [login to view URL] Target Smart Contract - Oracle Router Type [login to view URL] Target Smart Contract - Aave Strategy Type [login to view URL] Target Smart Contract - Compound Strategy Type [login to view URL] Target Smart Contract - Convex Strategy Type [login to view URL] Target Smart Contract - Convex OUSD Metastrategy Type [login to view URL] Target Smart Contract - Morpho Strategy Type [login to view URL] Target Smart Contract - OGV Type [login to view URL] Target Smart Contract - veOGV Type [login to view URL] Target Smart Contract - OGV Inflation Controller Type [login to view URL] Target Smart Contract - Governor / Timelock Type [login to view URL] Target Smart Contract - OGN Buyback Type [login to view URL] Target Smart Contract - OGN Staking Type [login to view URL] Target Smart Contract - OUSD Swap Type [login to view URL] Target Smart Contract - Harvester Type [login to view URL] Target Smart Contract - Dripper Type [login to view URL] Target Smart Contract - OETH Token Type [login to view URL] Target Smart Contract - wOETH Token Type [login to view URL] Target Smart Contract - OETH Vault Type [login to view URL] Target Smart Contract - OETH Frax Staking Strategy Type [login to view URL] Target Smart Contract - OETH Harvester Type [login to view URL] Target Smart Contract - Convex OETH Meta Strategy Type [login to view URL] Target Smart Contract - OETH Dripper Type [login to view URL] Target Websites and Applications Type Vulnerability List So after you’re done with your analysis on the Assets in Scope tell me alongside your POC if the vulnerability includes one or more of the following and your POC Solving it: On Smart Contracts: 1. Any governance voting result manipulation 2. Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield 3. Permanent freezing of funds 4. Protocol Insolvency 5. Theft of unclaimed yield 6. Permanent freezing of unclaimed yield 7. Temporary freezing of funds On the Website or Application: 1. Ability to execute system commands 2. Stealing User Cookies 3. Signing transactions for other users 4. Redirection of user deposits and withdrawals 5. Subdomain takeover resulting in financial loss (applicable for subdomains with addresses published) 6. Wallet interaction modification resulting in financial loss 7. Direct theft of user funds 8. Tampering with transactions submitted to the user’s wallet 9. Submitting malicious transactions to an already-connected wallet 10. Spoofing content on the target application (Persistent) 11. Users Confidential information disclosure such as Email 12. Privilege escalation to access unauthorized functionalities
ID Proyek: 37155591

Tentang proyek

19 proposal
Proyek remot
Aktif 7 bulan yang lalu

Ingin menghasilkan uang?

Keuntungan menawar di Freelancer

Tentukan anggaran dan garis waktu Anda
Dapatkan bayaran atas pekerjaan Anda
Uraikan proposal Anda
Gratis mendaftar dan menawar pekerjaan
19 freelancer menawar dengan rata-rata $8.370 USD untuk pekerjaan ini
Avatar Pengguna
We propose a comprehensive cybersecurity assessment of your assets in scope, including smart contracts and web applications. Our team of experienced ethical hackers will conduct a thorough analysis to identify vulnerabilities and provide Proof of Concepts (POCs) for each. For the smart contracts, we will focus on assessing potential risks such as governance manipulation, fund theft, freezing of assets, protocol solvency, and more. We are committed to ensuring the security of your assets and preventing loss or exploitation. Additionally, we will scrutinize the web application for system command execution, cookie theft, transaction manipulation, subdomain takeover, and other potential threats. Our aim is to fortify your digital presence, safeguard user data, and protect against financial losses. Our approach combines manual and automated testing, utilizing industry-leading tools and techniques. We will deliver a detailed report outlining vulnerabilities and recommended solutions, ensuring your assets are resilient against emerging threats. With our expertise and commitment to security, we look forward to establishing a long-term partnership to protect your digital assets and maintain trust in your systems. Thanks Rahul S.B
$10.000 USD dalam 60 hari
5,0 (10 ulasan)
7,4
7,4
Avatar Pengguna
Dear Client, We hope this proposal finds you well. On behalf of N&T Negocios y Tecnologias s.r.l., we would like to express our interest in working on the Vulnerability Tester project. With over 20 years of experience in the IT industry, specializing in web, mobile, blockchain, and AI development projects, we believe we have the expertise and skills necessary to successfully carry out this project. Our proposal for the Vulnerability Tester project includes the following solutions: 1. Conducting a comprehensive assessment of the smart contracts and applications listed in the "Asset in Scope" section to identify vulnerabilities and potential risks. 2. Developing and implementing a Proof of Concept (POC) based on the guidelines and rules provided in the POC Guidelines and Rules document. 3. Creating POC templates following the guidelines outlined in the POC Templates Article. For the architecture and technology to be used, we recommend utilizing the following: 1. For smart contract analysis, we suggest using a combination of manual review and automated tools to identify vulnerabilities such as governance voting result manipulation, direct theft of user funds, permanent freezing of funds, protocol insolvency, theft of unclaimed yield, and temporary freezing of funds. 2. For website and application analysis, we propose employing a combination of vulnerability scanning tools, penetration testing techniques, and manual review to detect and mitigate vulnerabilities such as system command execution, stealing user cookies, signing transactions for other users, redirection of user deposits and withdrawals, subdomain takeover resulting in financial loss, wallet interaction modification resulting in financial loss, direct theft of user funds, tampering with transactions submitted to the user's wallet, submitting malicious transactions to an already-connected wallet, spoofing content on the target application, users' confidential information disclosure, and privilege escalation to access unauthorized functionalities. We understand that the budget for this project is approximate and will be determined based on the scope of work required. We assure you that our team will work diligently to deliver exceptional results within the allocated budget. We are excited about the possibility of collaborating with you on the Vulnerability Tester project. We believe that our extensive experience, commitment to quality, and dedication to client satisfaction make us the ideal choice for this project. Please do not hesitate to reach out to us with any questions or further details regarding the project. We eagerly await your response and the opportunity to discuss this project further. Thank you for considering N&T Negocios y Tecnologias s.r.l. for this project. Best regards, N&T
$9.000 USD dalam 45 hari
5,0 (6 ulasan)
6,3
6,3
Avatar Pengguna
Hello Victor N, I have thoroughly reviewed your project requirements and I'm fully prepared to meet your criteria. Here's what I've done to align with your instructions: I've carefully read all the sections provided. I've identified vulnerabilities in the smart contracts and the website/application. I've created a POC based on your guidelines and rules. My expertise in Java, Solidity, security, and Smart Contracts positions me to deliver effective results. I'm ready to discuss the details and showcase my findings. Let's connect to take this forward and explore long-term collaboration opportunities. Let's connect via a telephonic conversation or Zoom meeting to delve into the specifics. Your project's success is my priority. Best regards, Rakhi
$7.500 USD dalam 7 hari
5,0 (4 ulasan)
6,5
6,5
Avatar Pengguna
Hello, my name is Adeel and I am an experienced Java developer with over 8 years of experience in the industry. I have worked on a variety of projects including Python, Django, React, React Native, and data science. I have also trained on machine learning using Tensorflow and Keras. I understand that you are looking for someone to conduct vulnerability testing on your smart contracts and applications and I believe that I am the best fit for this project. With my experience in Java, Python, Django, React, React Native, and data science as well as penetration testing and vulnerability assessment I am confident that I can find vulnerabilities on either the smart contracts or apps that prevent losses of funds, loss of more than 10% of yield freezing of funds that cannot be undone by admin actions ability for an unauthorized user to use admin actions governance process failures redirected funds by address modification shell access on server injection of text
$7.500 USD dalam 20 hari
5,0 (19 ulasan)
5,6
5,6
Avatar Pengguna
Hello There! I am a Certified Ethical Hacker and PenTester. The Number 1 Cybersecurity Engineer on here. With 10+ years of experience in Providing Cyber Security related services. I would like to work with you to detect the security weakness in your Smart Contracts before the hackers do it. Please start the chat so i can show you some sample reports of my previous report. Right now I am placing a placeholder bid, We will decide the price and time after discussion. Warm regards, Mohammed
$12.000 USD dalam 45 hari
5,0 (9 ulasan)
5,4
5,4
Avatar Pengguna
Hello, nice to meet you. I just read your job posting. I have lots of experience in this field, so you don't need found another one. If you give me a chance, I'll provide you with the perfect result. I want to more discuss with you via chat, Thank you. Tomas
$10.000 USD dalam 30 hari
4,1 (3 ulasan)
5,8
5,8
Avatar Pengguna
Dear Client, I hope this message finds you well. I am thrilled to submit my bid for the Vulnerability Tester project you have posted. As an experienced software engineer with a strong focus on Solidity, Java, Smart Contracts development, and security, I am confident in my ability to deliver exceptional results. I have carefully read the project description and reviewed the assets in scope. I understand that you require a freelancer who has already found a vulnerability in the listed assets and has a proof of concept (POC) to demonstrate it. I have gone through the POC guidelines and templates provided and I am fully prepared to meet your requirements. Before discussing pricing and timeline, I kindly request the opportunity to connect with you in chat to discuss the project requirements more carefully. This will allow me to fully understand your expectations and provide a tailored proposal that aligns with your needs. I am particularly excited to work with clients from Turkey, as I appreciate the cultural diversity and the opportunity to collaborate with individuals from different backgrounds. Thank you for considering my proposal. I look forward to the opportunity to discuss the project further in chat. Best regards,
$8.300 USD dalam 7 hari
0,0 (0 ulasan)
0,0
0,0

Tentang klien

Bendera TURKEY
Famagusta, Turkey
5,0
3
Memverifikasi Metode pembayaran
Anggota sejak Jan 20, 2020

Verifikasi Klien

Terima kasih! Kami telah mengirim Anda email untuk mengklaim kredit gratis Anda.
Anda sesuatu yang salah saat mengirimkan Anda email. Silakan coba lagi.
Pengguna Terdaftar Total Pekerjaan Terpasang
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Memuat pratinjau
Izin diberikan untuk Geolokasi.
Sesi login Anda telah kedaluwarsa dan Anda sudah keluar. Silakan login kembali.