2026年10月05日に公開 · 2026年10月05日時点で募集中であることを確認済みです
この企業はあなたの会社ですか?€ 1.000 – € 4.000 /案件
We need an independent security review of a new member app (React Native / Expo) and its PHP JSON API. This is not a redesign or a feature build. The previous generation of this product had a serious incident (personal data exposed). That stack is retired. We want a review of the new app and API before a wider release. This is a small member app for people who already belong to a venue/club. It is not a marketplace, social network, or payments app. What it does today (this is the whole product): - Sign in, create account, verify email, reset password (reset is a simple web page) - 8 languages - Accept terms when they change - Home: greeting, shortcuts; optional club “home” when a club is selected - Clubs: list of linked clubs, pending/unavailable states, add a club with a code (connects an existing membership; staff finish the link) - Profile: name, photo if the club has one, credit, member type, membership status, QR to show on site - Log out What it does not do: - No chat, feed, map, camera KYC, in-app payments, or admin tools - No browsing or “joining” random clubs from the app - Staff-side club software is a separate system and is out of scope unless we say otherwise Size (for quoting): - One React Native / Expo app (iOS + Android, same code) - A small PHP JSON API: on the order of ~12 endpoints (login, session, register, password reset, profile, add-club, languages, etc.) - A few static web pages (verify email, reset password) We expect a short, time-boxed review (days, not weeks), not a full enterprise pentest, unless you explain why more time is needed. What we will provide (after hire, not in this post): - TestFlight / Android preview builds - A throwaway member account - Read-only or time-limited access to the API source and app source under NDA - A written scope and rules of engagement In scope: - iOS and Android client (same codebase) - Public HTTPS API used by the app (login, session, registration, password reset, profile, club linking) - Auth: passwords, sessions, email verification, password reset - Access control: one member must not read or change another member’s data or another club’s data - Secrets in the client, local storage, logging - Transport (HTTPS), session handling, rate limiting, common API issues (auth bypass, IDOR, injection, mass assignment) - High-level review of server exposure of private folders / config (no full infra pentest unless agreed) Out of scope (unless we agree in writing): - Denial of service / load testing - Other products or domains we have not named - Phishing our staff or testers - Accessing real customer or club production data - Social engineering - Publishing findings before we have had time to fix them What we are not asking for: - A rewrite of the app - “Unpack the APK and send us exploits” - A generic automated scan dump with no explanation Deliverables: - A written report: findings, severity (e.g. Critical / High / Medium / Low / Info), affected endpoint or component, impact, and a clear fix recommendation. - A short call to walk through the report. - Re-test of issues we mark as fixed (within an agreed window). How you should work: - Time-boxed (please bid a number of days, not “until we find something”). - Use only the test account and systems we name. - Stop and tell us immediately if you find live personal data you should not have. - No public write-up or CVE without our written OK. Please include in your bid: - 2–3 similar mobile + API reviews (no need to name clients if under NDA) - Whether you prefer source-assisted or black-box, and why - Your report sample (redacted is fine) - Fixed price and number of days - Confirmation you will sign an NDA - We will not share production admin credentials or the live database with freelancers. Testers use a dedicated account.
無料アカウントを作成すると、求人の全文を見て応募できます。