Find Jobs
Hire Freelancers

SQL injection/Web security expert -- 2

$30-250 USD

Terminado
Publicado hace alrededor de 3 años

$30-250 USD

Pagado a la entrega
We need you to penetrate the following case scenario: Suppose there is a PHP script file "[login to view URL]" which takes a param i.e $_GET["profilePic"], which is image file path and then it generates a PDF with this image using FPDF library. If the image file doesn't exist, it will throw an error like: Warning: getimagesize(uploads/X/[login to view URL]): failed to open stream: No such file or directory in /home/X/public_html/[login to view URL] on line 1202 FPDF error: Missing or incorrect image file: uploads/X/[login to view URL] We need a proof of concept that this unhandled warning can result into server being pwned/allowing execution of PHP code. You will be rewarded with a bounty and this may lead to more projects in future!
ID del proyecto: 29428134

Información sobre el proyecto

10 propuestas
Proyecto remoto
Activo hace 3 años

¿Buscas ganar dinero?

Beneficios de presentar ofertas en Freelancer

Fija tu plazo y presupuesto
Cobra por tu trabajo
Describe tu propuesta
Es gratis registrarse y presentar ofertas en los trabajos
Adjudicado a:
Avatar del usuario
Hi, As per our discussion yesterday I am already working on this and I expect this to be completed by 9 pm. I will share the report to you. Kindly initiate personal chat to discuss. Thanks Avinash
$50 USD en 7 días
4,7 (4 comentarios)
3,7
3,7
10 freelancers están ofertando un promedio de $161 USD por este trabajo
Avatar del usuario
Hello Sir. I can do this project right now. I am a professional Linux and developer in PHP, Wordpress, Laravel, Magento, Joomla, Prestashop, OpenCart, Yii, NodeJS, Angular, Vue.js, HTML5, CSS3 and jQuery. I can do this project. Please hire me. I think, You will contentment with my skills. I can fix your site issue successfully. I am looking forward to having further discussions with you and can start working immediately. Thank you
$120 USD en 1 día
5,0 (68 comentarios)
6,0
6,0
Avatar del usuario
I am an experienced PHP / Ethical Hacker & Web developer I will FIX SQL injection/Web security issues as per your requirements with full satisfaction & unlimited revisions In order to any delay we'll refund your money Over the last 3 years, I have developed a wide range of Desktop apps and websites using JavaScript, HMTL, PHP, and MySQL And Desktop Applications Using C# and Vb.NET and Windows Forms including sites and Applications for startup companies and small businesses. Backend side: PHP5, Drupal, CodeIgniter, Wordpress, Laravel, Node.js Front End Side: HTML5/CSS3/SASS/SCSS/LESS JavaScript/ Jquery Databases: MySQL, MongoDB, Oracle API's: Twitter API, LinkedIn API, PayPal API, Payoneer API etc.
$150 USD en 4 días
5,0 (24 comentarios)
4,5
4,5
Avatar del usuario
Hi There, This is Mohammad from brief I summarize that you need a SQL injection/Web security expert Right? Sure i'll provide you with Quality Work. Please award me the project so that we can discuss it more. I am a Full Stack Engineer with 15 years of experience. I have worked on several similar projects You can see Ratings and Reviews from Client here: www.freelancer.com/u/irfanui Thanks.
$250 USD en 25 días
4,8 (4 comentarios)
2,8
2,8
Avatar del usuario
Hi, I've read your project details. I'm currently unable to response you via chat due to the following reason. "Unfortunately, you are not allowed to send a message to this thread." I can pentest your file for SQLi or other vulnerabilities. You need to provide me your web URL to check the vulnerability. Let me know if you are interested. Thanks.
$85 USD en 3 días
5,0 (2 comentarios)
2,1
2,1
Avatar del usuario
Hi There, This actually sounds more like a Local File Inclusion (LFI) issue rather than SQL injection (the error isn't a SQL error...). Depending the version of PHP that is in use I have a few ideas on how you could pwn this server. I am a professional penetration tester and would be happy to test this for you.
$200 USD en 3 días
0,0 (0 comentarios)
0,0
0,0
Avatar del usuario
Hello, I am happy to share keen interest in working with you on this exciting opportunity as I have relevant experience to complete this project as per mentioned requirements. I am ready to start immediately and will be available full time for you. I ensured perfect work till now as you can see in my profile and would like to help you by doing my best. we are Professional and quality work is my prime concern. - I will complete all of your requirements - I will do more tweaks for you as well I ensure you that I am best suit for this post. Please open chat with me so we can discuss more in details.
$200 USD en 10 días
0,0 (0 comentarios)
0,0
0,0
Avatar del usuario
Hi there, I have read your requirements and would like to tell you that I am a part-time freelancer and work on these technologies (Laravel (5 / 6 / 7), WordPress (4 / 5), Cake (3), Yii (1 / 2), Core PHP and many more) for more than 4+ years. I am very much competent with Frameworks but have very good experience with others listed technologies as well. I have made many projects for schools, businesses, non profit companies, small start-up companies, personal blogs and many more custom systems. We can talk more about my availability and how we will be working on the project. I would like to know when can we discuss more about your project and can get started? Hope to hear from you soon! Good day!
$195 USD en 10 días
0,0 (0 comentarios)
0,0
0,0
Avatar del usuario
Hi, I have 17 years of experience in web development and 7 years is Security. There are certain techniques that can be used to try to pwn the server but I will need to test them out, because a warning only shows certain aspects of how the code is handled. However, if the code around that warning is written properly, then this error cannot be leveraged. Is there a way I can actually test that web application? Regards, Jean-Yves
$222 USD en 3 días
0,0 (0 comentarios)
0,0
0,0

Sobre este cliente

Bandera de PAKISTAN
Khanewal, Pakistan
5,0
23
Forma de pago verificada
Miembro desde may 12, 2013

Verificación del cliente

¡Gracias! Te hemos enviado un enlace para reclamar tu crédito gratuito.
Algo salió mal al enviar tu correo electrónico. Por favor, intenta de nuevo.
Usuarios registrados Total de empleos publicados
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Cargando visualización previa
Permiso concedido para Geolocalización.
Tu sesión de acceso ha expirado y has sido desconectado. Por favor, inica sesión nuevamente.