Job Title: Web Security Tester / Penetration
I’m looking for an experienced web security tester to assist with a focused OTP and password-reset security assessment of a web application.
The main objective is to determine whether the application's OTP verification and password recovery mechanism can be bypassed, manipulated, or abused in a way that could allow an unauthorized password change.
A dedicated test acount is available for the assessment.
Testing focus:
OTP generation and verification logic
OTP expiry and one-time-use enforcement
OTP replay scenarios
OTP/session/account binding
Rate-limit enforcement and potential bypasses
Resend OTP behavior
Client-side vs server-side validation
HTTP request/response manipulation
Session and reset-token/state handling
Password-reset authorization
Alternative paths to the password-change stage
Logic flaws between OTP verification and password reset
Any confirmed path that could lead to account takeover
The application already implements controls such as OTP expiration and rate limiting, so the assessment should focus on whether these controls are properly enforced and whether the overall workflow can be bypassed through implementation or logic flaws.
This is a manual security assessment. Automated scanner results alone are not sufficient.