
Completed
Posted
Paid on delivery
Implementing 4 vulnerabilities in an already created project (WEB site), which should be difficult for other people to detect. The vulnerabilities should not be discoverable by AI tools, or LLMs More details: What kind of vulnerabilities do you want to implement? SQL Injection, Server-Side Request Forgery (SSRF) Examples for two Vulnerabilities (vulnerabilities must be of different types) Timing Attack — The safeCompare function looks like a proper implementation of secure comparison, but the if ([login to view URL] !== [login to view URL]) return false line immediately short-circuits when the lengths differ. An attacker can measure the differences in response time to first determine the exact length of the password, then deduce it character by character. Prototype Pollution — The deepMerge function does not filter the _proto_ key from the received object. An attacker can send {"_proto_": {"isAdmin": true}} in the request, modifying the global [login to view URL] and injecting properties into all objects created later in the application. How soon do you need your project completed? ASAP
Project ID: 40398248
9 proposals
Remote project
Active 13 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
9 freelancers are bidding on average $42 USD for this job

Hello, I can help you implement controlled and realistic vulnerabilities in your web application for testing and training purposes. With experience in web security and penetration testing, I can design subtle vulnerabilities such as SQL Injection and SSRF, along with other logic-based issues, in a way that reflects real-world scenarios while remaining stable and well-integrated into your application. My approach focuses on creating vulnerabilities that are not obvious through basic scanning tools, but still meaningful for advanced testing. I will also ensure each vulnerability is cleanly implemented and documented, including how it works and how it can be identified and mitigated. I’m available to start immediately and can deliver quickly. Best regards.
$150 USD in 7 days
2.4
2.4

Hello, I can help you build a safe, authorized security training version of your existing web project with intentionally vulnerable modules for learning, testing, or assessment purposes. I understand you need examples such as SQL Injection, SSRF, timing attack behavior, and prototype pollution, but I would only implement them in a controlled sandbox or training branch, not in production code. My Technical Approach: Controlled Lab Setup: I will add vulnerable endpoints only in an isolated environment, separated from real users, production data, and external systems. Multiple Vulnerability Types: I can create realistic examples of SQL Injection, SSRF, timing attacks, and prototype pollution, each as a separate module. Documentation: I will provide clear notes explaining how each vulnerability works, how it can be tested, its impact, and how to fix it. Secure Fixes: I can also include patched versions so the vulnerable and secure implementations can be compared. Why work with me? I have strong experience with web security, backend logic, and secure coding practices. I focus on practical, clean, and well-documented work that is useful for ethical security training and assessment.
$10 USD in 3 days
2.4
2.4

Being a fully stacked web developer with over a decade of experience, I understand the importance of security and the potential risks vulnerabilities can pose to your website. I have extensive knowledge in various types of web vulnerabilities such as SQL injection, Server-Side Request Forgery (SSRF), Timing Attack, and ProtoType Pollution - all skills that are directly aligned with your project requirements. Moreover, my commitment to fast yet secure project delivery means that once we engage, your project will be prioritized and executed in a timely manner without compromising its integrity. Having successfully handled over a hundred similar projects, my clients constantly commend my work approach as result-oriented and consistent. So if you're seeking reliability, experience, and a professional who will take your website security to new heights, then let's join forces. Together we can create a secure-yet-transformative digital solution tailored specifically for your needs. Let's make your vision a secure reality!
$49 USD in 1 day
2.0
2.0

Hello, My name is Dmytro and I have over 10+ years of experience in delivering secure, scalable, and AI-enhanced SaaS platforms. Throughout my career, I have developed a keen eye for identifying vulnerabilities and implementing robust security measures. One of my core strengths is working in real-time, interactive systems which include securing WebSockets, Redis Pub/Sub, and high-throughput notification engines similar to what your project entails. As you mentioned, it is crucial for the vulnerabilities to not be easily detectable by AI tools or LLMs. I take pride in my ability to think outside the box and devise creative solutions to problems. Even with the provided examples of Timing Attack and Prototype Pollution, let me assure you that I will come up with unique vulnerabilities that would be challenging for any outsider to easily pinpoint. Further affirming my fit for this project is my skillset in penetration testing and web security, which has constantly exposed me to diverse threats against web applications. I understand the significance of this task being time-sensitive and would be able to deliver ASAP without compromising quality or leaving technical debts behind. My work methodology is allembracing from providing architectural diagrams to post-production documentation facilitating complete visibility into the project. In summary, by choosing me for this project, you can expect a thorough understanding of your current Thanks!
$15 USD in 1 day
0.0
0.0

Hi, I understand your requirement to implement specific vulnerabilities (such as SQL Injection and SSRF) in an existing web application for testing or educational purposes. I have experience in network security, firewall configurations (Fortinet, Palo Alto), and understanding real-world attack vectors and misconfigurations. I can help design and implement controlled, intentional vulnerabilities in a safe and structured way within a non-production environment. I will ensure: - Each vulnerability is properly implemented and testable - It aligns with realistic attack scenarios - Clear documentation is provided (how it works, impact, and mitigation) I also understand how modern security tools and scanners detect vulnerabilities, so I can structure implementations in a way that reflects real-world complexity for learning and testing purposes. Let me know more about your tech stack and requirements. I’m available to start immediately. Thanks
$18 USD in 7 days
0.0
0.0

Hello, I can help you implement realistic and hard-to-detect vulnerabilities in your existing web application as per your requirements. I have experience in web security, penetration testing, and secure coding practices, which allows me to design vulnerabilities that mimic real-world scenarios while avoiding easy detection by automated tools or LLMs. I will implement vulnerabilities such as SQL Injection, SSRF, timing attacks, and prototype pollution with proper logic so they appear legitimate and require manual analysis to discover. I will also ensure that each vulnerability is of a different type and properly integrated into your existing codebase without breaking functionality. I can complete this project quickly and deliver clean, well-documented work. Let’s discuss your project in detail so I can start immediately. Thank you.
$25 USD in 10 days
0.0
0.0

Why settle for a dev when you can hire a Ghost? Most "experts" will hand you textbook bugs that a basic AI scanner flags in seconds. You don’t need loud, amateur mistakes. You need craftsmanship. You need logic so smooth it looks like a high-end feature, but behaves exactly how you want it to when the time comes. I’m talking about "Invisible Engineering." I’ll weave those SQLi and SSRF flaws into your architecture so they look like standard optimizations or utility functions. To an LLM, it’s just clean, professional code. To you? It’s a precision tool. The Strategy: Stealth-First: I implement flaws—like the Timing Attack or Prototype Pollution you mentioned—using "innocent" logic that mimics your existing coding style. No red flags, no loud comments. AI-Proof: Scanners look for patterns. I build bespoke, structural logic that bypasses automated detection by hiding the vulnerability within standard operational flows (like a "Remote Asset Loader" for your SSRF). Plug-and-Play: I keep it lean. No massive rewrites. I’ll provide the exact, professional snippets you can drop into your project today. You said you need this ASAP. I don’t sit around waiting for the grass to grow. I’m ready to deliver the "optimizations" right now so you can get the win and move on. Don’t hire a guy who’s going to get you caught. Hire the guy who makes it look like it was meant to be there all along. Let's get to work.
$20 USD in 2 days
0.0
0.0

Bucharest, Romania
Payment method verified
Member since Jan 9, 2025
€8-30 EUR
€8-30 EUR
$10-30 USD
£50-500 GBP / hour
$250-750 USD
₹500000-1000000 INR
$10-30 USD
₹12500-37500 INR
₹12500-37500 INR
$10-30 USD
$250-750 USD
€250-750 EUR
$12-30 SGD
₹600-1500 INR
₹12500-37500 INR
$30-250 USD
$15-25 USD / hour
$15-25 USD / hour
$30-250 USD
$25-50 USD / hour
$250-750 USD
$30-250 USD