
Open
Posted
•
Ends in 2 days
Paid on delivery
My esports tournament platform needs a thorough penetration test completed within four days. The stack combines a Supabase/PostgreSQL back end, REST/GraphQL-based APIs, user accounts, an admin console, and a wallet that handles deposits, withdrawals, and payment-gateway traffic. Primary focus is the payment gateway and wallet layer, yet I still want every public or privileged surface probed against the full OWASP Top 10 as well as common esports-specific attack patterns. That includes: authentication and authorization flows, admin privilege escalation, API abuse, IDOR, SQLi, XSS, insecure file uploads, exposed secrets, and verification of Supabase row-level security. Attempted manipulation of balances or tournament results is welcomed if it highlights a weakness. When the engagement ends I expect a full vulnerability report. It should rank findings by risk, reproduce each issue step-by-step, and supply clear remediation advice. Screenshots or PoC scripts are highly appreciated. Please respond only if you have hands-on web penetration testing experience and can commit to the four-day window; automated scans alone will not be sufficient.
Project ID: 40570777
44 proposals
Open for bidding
Remote project
Active 21 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
44 freelancers are bidding on average $36 USD for this job

Hi, I can help with your "Esports Site Penetration Test Audit" project. I develop clean, maintainable PHP backends — core PHP and Laravel/Symfony, MySQL schema design, and well-structured REST APIs. For work involving php, web security, testing / qa, postgresql, internet security, penetration testing, api testing, rest api, I pay close attention to validation, security, and readable code, delivering in small, testable milestones. I provide clean commits and clear documentation. Could we discuss the specifics before I firm up the timeline? ⭐ 5.0/5 from a recent client: "it was great working with him, did whatever changes i asked him as per my need." Final timeline and cost will be confirmed in chat after a complete understanding and documentation of the project expectations in detail.
$24 USD in 1 day
7.4
7.4

As a seasoned full-stack developer specializing in PHP and PostgreSQL, I am uniquely qualified to handle your esports site penetration test. With my extensive experience handling REST and GraphQL-based APIs and designing user account systems, I not only understand the intricacies of payment gateways and wallets but also the potential vulnerabilities associated with them. Having been a part of successful projects including RoI maximization systems, which required deep knowledge of database security, I am well-versed in investigating issues related to SQL injection (SQLi) and insecure file uploads. My proficiency extends to web development, underpinned by detailed knowledge of React and Node.js frameworks – a perfect fit for your Supabase/PostgreSQL stack. I assure you this won't be just another automated scan; instead, a four-day intensive yet meticulous manual probe targeted towards identifying risks from an OWASP Top 10 perspective as well as any intricate esports-specific attack patterns that may pose threats to your platform. Finally, you can count on me for a clear, detailed vulnerability report with actionable remediation steps at the end of it all. I'm eager to get started on securing your platform!
$20 USD in 7 days
6.9
6.9

Hello, I have 9 years of experience in cybersecurity, specializing in web application, API, and infrastructure penetration testing. I can perform a comprehensive manual security assessment of your esports tournament platform within the required 4-day timeframe. My assessment will focus on the payment gateway and wallet functionality while thoroughly testing the entire application for OWASP Top 10 vulnerabilities, API security issues, authentication and authorization flaws, privilege escalation, IDOR, SQL injection, XSS, insecure file uploads, exposed secrets, Supabase Row-Level Security (RLS), and esports-specific business logic vulnerabilities, including attempts to manipulate balances and tournament outcomes where appropriate. You'll receive a detailed professional report containing risk-rated findings (CVSS), step-by-step reproduction, screenshots/PoCs where applicable, impact analysis, and practical remediation recommendations. My methodology follows OWASP WSTG, PTES, and industry best practices, with an emphasis on manual testing rather than relying solely on automated scanners. I can start immediately and dedicate the required time to complete the engagement within your deadline. Best regards, Kajal Majhi Cybersecurity & Penetration Testing Specialist
$500 USD in 7 days
5.3
5.3

I’ve done hands-on pentesting for web apps with wallets and custom admin panels—lately on a production fantasy league (confidential; demo by call only) that also used a Postgres backend, API layer, and payment flow. My approach is manual-first. I attack auth and wallet layers, escalate roles, probe API endpoints for IDOR and rate limit bypass, throw raw payloads for SQLi/XSS, and validate Supabase Row Level Security with direct queries and fuzzing. Payment gateway and game result manipulation get full manual attention. Automated tools only supplement manual findings. You’ll get a ranked, step-by-step report with PoC scripts or screenshots for every issue, prioritized by actual risk. Does your stack already have staging environment parity with production, or do you want testing on live? Pradeep
$20 USD in 7 days
5.0
5.0

Hi , Good afternoon! I’ve carefully checked your requirements and really interested in this job. I’m full stack node.js developer working at large-scale apps as a lead developer with U.S. and European teams. I’m offering best quality and highest performance at lowest price. I can complete your project on time and your will experience great satisfaction with me. I’m well versed in React/Redux, Angular JS, Node JS, Ruby on Rails, html/css as well as javascript and jquery. I have rich experienced in PostgreSQL, REST API, Testing / QA, API Testing, PHP, Web Security, Internet Security and Penetration Testing. For more information about me, please refer to my portfolios. I’m ready to discuss your project and start immediately. Looking forward to hearing you back and discussing all details.. With regards
$25 USD in 4 days
4.6
4.6

I understand how important it is to protect your gaming platform against potential vulnerabilities that may compromise its integrity or risk user information. As a skilled web developer with expertise in web security, I possess the hands-on experience and understanding needed to carry out an in-depth penetration test on your esports tournament platform. My robust proficiency with databases, including PostgreSQL, front-end frameworks like React.js, back-end technologies such as Node.js, and my familiarity with REST API suits well with your project requirements. In my decade-long career, I have been known for delivering reliable, maintainable, and scalable solutions tailored strategically towards driving business growth and enhancing user engagement. Having worked extensively on platforms integrating payment-gateway traffic with secure wallet functions, I am especially well-versed in the complexities of this particular area of your platform. This puts me in an excellent position to thoroughly test the different layers - not only payment gateway and wallet aspects but also every public and privileged surface - for potential weaknesses.
$20 USD in 2 days
5.0
5.0

Hello there, I read your requirements carefully. I have hands on experience performing manual web application security assessments, and I can commit to your four day timeline. My approach goes far beyond automated scanners, focusing on real world exploitation of authentication, authorization, payment flows, API security, Supabase RLS, IDOR, privilege escalation, and wallet manipulation to uncover the actual root cause of vulnerabilities. I have worked on secure Node.js, React, PostgreSQL, API driven platforms, and payment integrations where security and data integrity were critical. Could you please let me know if testing will be performed against a staging environment or the live platform? I am ready to start immediately and deliver a detailed vulnerability report with reproducible findings, risk ratings, PoCs, and practical remediation steps. Thanks, Raghu
$20 USD in 7 days
4.8
4.8

With my expertise in PHP, REST API, and Node.js, I can offer you not just a thorough penetration testing but also peace of mind. Over the years, I’ve honed my skills in full-stack development and web scraping that enables me to understand the intricacies of different systems. Your complex Esports platform won't pose much challenge to me Since I specialize in developing efficient and scalable applications while prioritizing user-friendliness. Moreover, I'm well-versed with Vue.js, which can be an added advantage when it comes to detecting vulnerabilities like XSS and insecure file uploads. The fact that you desire a hands-on approach rather than relying on automated scans resonates with my beliefs; diligent manual testing is the key. I understand your need for a vulnerability report that provides clear remediation advice and reproduces each issue step-by-step. Rest assured, as a results-driven professional I'll provide you with nothing but the best. Choose me for this project, and I guarantee you prompt delivery of a comprehensive report covering everything from OWASP Top 10 vulnerabilities to specific Esports scenarios. Let's work towards making your platform absolutely bulletproof.
$30 USD in 1 day
4.1
4.1

I will conduct a thorough penetration test of your esports tournament platform, focusing on the payment gateway and wallet layer, as well as probing authentication and authorization flows, admin privilege escalation, and API abuse, using REST and GraphQL-based APIs, and testing against the OWASP Top 10, providing a full vulnerability report with ranked findings, step-by-step reproduction, and remediation advice, happy to discuss further over DM.
$30 USD in 1 day
4.7
4.7

Hi, I have hands-on experience in manual web application penetration testing, API security testing, and security validation for Supabase/PostgreSQL applications, and I can complete this engagement within your 4-day timeline. I will thoroughly test the payment gateway, wallet, REST/GraphQL APIs, authentication, authorization, admin panel, and Supabase Row-Level Security against the OWASP Top 10, including IDOR, privilege escalation, SQLi, XSS, file upload issues, exposed secrets, and business logic flaws. Beyond automated tools, I perform manual testing to uncover complex vulnerabilities such as balance manipulation, tournament result tampering, and API abuse that scanners often miss. You'll receive a detailed vulnerability report with risk ratings, reproduction steps, screenshots/PoCs where applicable, and practical remediation recommendations. I communicate progress throughout the engagement and can start immediately to ensure delivery within the required timeframe. Looking forward to helping secure your esports platform before launch.
$25 USD in 7 days
3.6
3.6

Hello, I have hands-on experience with web application security testing and can complete a thorough penetration test within your four-day timeline. My approach combines manual testing with industry-standard security tools to identify real, exploitable vulnerabilities rather than relying solely on automated scans. I'll assess your esports platform against the OWASP Top 10, with particular focus on the wallet and payment gateway, while also evaluating authentication and authorization, API security (REST/GraphQL), Supabase Row-Level Security, IDOR, privilege escalation, SQL injection, XSS, insecure file uploads, exposed secrets, and business logic flaws such as balance or tournament result manipulation. The engagement will conclude with a detailed vulnerability assessment that includes risk ratings, reproduction steps, supporting screenshots or proof-of-concept evidence where applicable, impact analysis, and practical remediation recommendations prioritized by severity. I understand the importance of responsible testing, clear communication, and meeting deadlines, and I'm available to begin immediately and deliver within the required four-day window. Thank you & Best Regards Naveen
$20 USD in 7 days
3.2
3.2

I will conduct a thorough penetration test of your esports tournament platform within the four-day window—covering the Supabase/PostgreSQL backend, REST/GraphQL APIs, admin console, and wallet/payment gateway layer. My Approach: 1. Full OWASP Top 10 Testing: I will test against the latest OWASP Top 10 (2025) including Broken Access Control, Injection, Authentication Failures, and Security Misconfigurations . I will probe admin privilege escalation, IDOR, SQLi, XSS, and exposed secrets. 2. API Abuse & GraphQL: I will test REST endpoints and GraphQL queries for injection, rate limiting bypasses, and authorization flaws. 3. Supabase-Specific Testing: I will verify Row Level Security (RLS) policies on your PostgreSQL database and test GoTrue authentication for privilege escalation . 4. Wallet & Payment Gateway Focus: I will attempt balance manipulation, transaction replay, and payment gateway bypasses—applying common financial attack patterns . 5. Reporting: I will deliver a full vulnerability report ranking findings by risk, with step-by-step reproduction, screenshots/PoC scripts, and clear remediation advice . Timeline: 6 days from access handover. Need: API endpoints, admin URLs, test credentials, and Supabase project access. Share access details—I will begin immediately and deliver a comprehensive, actionable report.A
$28 USD in 7 days
3.9
3.9

Hi! Experienced web penetration tester here hands-on, not just automated scans. I can commit fully to your four-day window. I'll prioritize the payment gateway and wallet layer (deposit/withdrawal logic, balance manipulation, race conditions), then probe every surface against the full OWASP Top 10: auth flows, IDOR, SQLi, XSS, privilege escalation, file uploads, exposed secrets, and Supabase RLS verification. You'll get a risk-ranked report with step-by-step reproductions, PoCs, and remediation. Let's secure it!
$29 USD in 4 days
3.1
3.1

Hi, I can conduct a thorough penetration test on your esports tournament platform, focusing on the payment gateway and wallet layer, as you requested. I have extensive hands-on experience with OWASP Top 10 vulnerabilities and have tested similar platforms featuring Supabase/PostgreSQL and REST/GraphQL APIs. During my last project, I identified critical vulnerabilities in a payment processing system and delivered a detailed report with prioritized findings and remediation steps. I'm ready to commit to the four-day timeline and can provide a full vulnerability report with visuals and PoC scripts. How do you prefer to communicate during the testing process? I’m looking forward to collaborating! $[Price] in 3 days.
$17 USD in 3 days
2.7
2.7

Hello, I have extensive hands-on experience in web application penetration testing and API security assessments, with a strong background in testing modern applications built on PostgreSQL, REST/GraphQL APIs, and authentication platforms such as Supabase. I have performed comprehensive manual penetration tests for applications involving payment processing, digital wallets, multi-tenant environments, and administrative portals, focusing on real-world attack scenarios rather than relying solely on automated scanners. My assessment will thoroughly evaluate the entire attack surface, including the payment gateway and wallet functionality, authentication and authorization mechanisms, privilege escalation, IDOR, SQL injection, XSS, insecure file uploads, exposed secrets, Supabase Row-Level Security (RLS), business logic flaws, and attempts to manipulate wallet balances or tournament results where permitted. Upon completion, you will receive a professional penetration testing report with risk-ranked findings, detailed reproduction steps, supporting evidence (screenshots and proof-of-concept where applicable), and practical remediation recommendations aligned with industry best practices. I am ready to start immediately, can dedicate the necessary time to this engagement, and am confident in delivering a high-quality assessment and final report within your required four-day timeframe. Best Regards, Sherif
$100 USD in 4 days
3.1
3.1

I see you need a penetration test for your esports tournament platform in just four days. With my skills in REST API and PostgreSQL, I can help identify any vulnerabilities quickly. What specific areas are you most concerned about?
$18 USD in 7 days
2.5
2.5

Your focus on securing the wallet and payment gateway aligns well with my experience in testing PostgreSQL and Supabase setups. I’ve performed comprehensive OWASP Top 10 audits on similar platforms, including testing for IDOR, SQLi, XSS, and privilege escalation. My approach involves manual testing of authentication flows, API endpoints, and security controls, supplemented by targeted scripts to identify vulnerabilities like API abuse or insecure file uploads. In my previous role, I uncovered critical flaws that could have allowed balance manipulation and unauthorized admin access, leading to immediate remediation. I’ll deliver a detailed report with step-by-step reproduction, risk ratings, and clear fixes, supported by screenshots and PoC where applicable. Can you share whether you prefer a focus on the API layer first or the user interface during testing?
$20 USD in 7 days
0.6
0.6

Hi, there! I recently conducted a comprehensive penetration test for a gaming platform that involved a complex backend with user accounts, payment processing, and various API integrations. In that project, I focused on identifying vulnerabilities within the payment gateway and wallet functionalities, as well as ensuring robust authentication and authorization flows. A significant challenge was simulating real-world attack scenarios, including SQL injection and privilege escalation, while ensuring thorough documentation of each vulnerability found. This resulted in a detailed report that prioritized risks and provided actionable remediation steps, significantly enhancing the platform's security posture. I offer to perform a thorough penetration test on your esports tournament platform, focusing on the payment gateway and wallet layer while probing all public and privileged surfaces against the OWASP Top 10. My approach will include manual testing techniques to identify vulnerabilities such as API abuse and insecure file uploads, along with a comprehensive vulnerability report that ranks findings by risk and includes step-by-step reproduction and remediation advice. If I use my previous experience, your project will likely be completed successfully. Hope to discuss this in detail. Through detailed discussion, I think I can find the better solution to finish your project successfully. Thank you!
$20 USD in 7 days
0.5
0.5

Hi, For a platform handling wallets, payments, and tournament data, security testing needs to go beyond automated scanners. The real risks usually come from logic flaws—how users, admins, APIs, and financial flows interact. I would approach the audit with a manual-first security review covering: • Authentication and authorization testing • IDOR and privilege escalation checks • REST/GraphQL API abuse scenarios • Wallet balance manipulation attempts • Payment flow validation • Supabase/PostgreSQL security review including RLS policies • SQL injection, XSS, file upload, and exposed secret checks • Admin console and sensitive action testing The final report will include: ✔ Risk severity ranking ✔ Clear reproduction steps ✔ Evidence/screenshots where applicable ✔ Practical remediation recommendations My goal is not just to find vulnerabilities, but to provide your development team with actionable fixes before attackers discover them. I can complete the assessment within your four-day timeline and begin by mapping the application attack surface, APIs, and critical user flows.
$20 USD in 7 days
0.0
0.0

Hello, I can perform a comprehensive penetration test of your esports platform and deliver the audit within your 4-day timeline. My approach includes manual testing supported by industry-standard security tools, with a strong focus on your payment gateway, wallet logic, and Supabase security. I'll assess the application against the OWASP Top 10 and test authentication, authorization, API security (REST/GraphQL), IDOR, SQL injection, XSS, privilege escalation, file uploads, exposed secrets, and Supabase Row Level Security (RLS). I'll also verify whether wallet balances, payment flows, or tournament data can be manipulated. You'll receive: * A prioritized vulnerability report (Critical/High/Medium/Low) * Clear reproduction steps for every finding * Screenshots and PoC examples where applicable * Practical remediation recommendations * A final verification after fixes if required I have experience reviewing production web applications, backend APIs, and secure authentication systems, and I understand the importance of responsible testing with minimal disruption. I'm available to start immediately and can provide regular progress updates throughout the engagement.
$20 USD in 7 days
0.0
0.0

Karaganda, India
Payment method verified
Member since May 31, 2026
$10-30 USD
$10-30 USD
$30-250 USD
₹600-1500 INR
₹1500-12500 INR
₹12500-37500 INR
€6-12 EUR / hour
₹600-1500 INR
$10-30 USD
$10-30 USD
₹1500-12500 INR
$250-750 USD
₹750-1250 INR / hour
₹37500-75000 INR
$30-250 USD
€250-750 EUR
$10-30 USD
$1500-3000 USD
$30-250 USD
$750-1500 USD
₹1250-2500 INR / hour
₹1500-12500 INR
₹100-200 INR / hour
$3000-5000 AUD