Find Jobs
Hire Freelancers

NodeJS Security Expert Needed. CORs,DOS Protection,Hashing, and more

$30-250 USD

Cancelado
Publicado hace alrededor de 5 años

$30-250 USD

Pagado a la entrega
Hi, I need a NodeJS SECURITY EXPERT to apply all security suggested to run a production server. I have many articles relating to what Im looking for: [login to view URL]@nodepractices/were-under-attack-23-node-js-security-best-practices-e33c146cb87d [login to view URL]@tkssharma/secure-node-js-apps-7613973b6971 [login to view URL] I'm looking for someone that knows this stuff and has implemented before. I'm not looking for someone trying to learn on the job :). It will help if you know Mongo/Mongoose and possily AWS. Please put SENTRY (the error tracker I use) as the first words in your response so I know you read. Thanks
ID del proyecto: 18615488

Información sobre el proyecto

10 propuestas
Proyecto remoto
Activo hace 5 años

¿Buscas ganar dinero?

Beneficios de presentar ofertas en Freelancer

Fija tu plazo y presupuesto
Cobra por tu trabajo
Describe tu propuesta
Es gratis registrarse y presentar ofertas en los trabajos
Adjudicado a:
Avatar del usuario
SENTRY ;) I did a quick look through your code and came up with these. Concerns: Websockets are done over HTTP - Should be fixable in nginx config now I know how the code works [login to view URL] Ensure security groups are correctly set up to not permit access to redis/mongo/etc. except from prod VPC Package 'crypto' is unneedeed, should be replaced with node's builtin Package 'kleur' needs upgrading to package 'ansi-colors', should be a drop-in replacement Sentry doesn't work because it's not the first imported middleware - It needs to go above import authMiddleware from "./middlewares/auth"; 50mb size limit on picture uploads is a bit big, and should probably be ratelimited/limited total size per user. Check out how [login to view URL] is used Auth login limits, basic bruteforce protection DOS protection should be mainly done on the network side, but basic rate limiting can be implemented to reduce potential for abuse: [login to view URL] Payload validation: [login to view URL] Sensitive config (eg. salts, passwords) should be preferably stored in AWS SSM and grabbed during runtime You've already implemented CORS, but it might be worth setting up a URL whitelist when in DEV environment to make testing easier General code recommendations: I have a bunch but it wouldn't fit in the proposal. I'll format it properly in a word doc for you.
$100 USD en 3 días
5,0 (2 comentarios)
2,5
2,5
10 freelancers están ofertando un promedio de $173 USD por este trabajo
Avatar del usuario
Hi. i am a full web developer with over 5 years on freelancer.com. I have read your description and have interests in your project. I have rich experiences in projects similar to yours. I am ready for your project now. I would like to have a discussion on chat to get more about your project. Thanks. Best Regard
$150 USD en 3 días
4,8 (28 comentarios)
5,9
5,9
Avatar del usuario
Hi there! May Peace Be Upon You !! I am a certified ethical hacker and pen tester. I just love hacking and breaking the rules, but don’t get me wrong as I said I am an ethical hacker. @Certified at Ethical Hacking @Certified at WEB APP SECURITY FUNDAMENTALS @Certified at Website Hacking / Penetration Testing @Certified at Cyber Security Forensics Main Skills: Penetration Testing, Web Application Security. Social Engineering, Red team assessment, Ethical Hacking & Countermeasures, Malware Analysis. I provide a variety of security services including white/black hat penetration testing, network and host auditing, Policies and Business Impact Analysis. I will do OWASP Top 10 Application Security Pentesting. A1:2017-Injection A2:2017-Broken Authentication A3:2017-Sensitive Data Exposure A4:2017-XML External Entities (XXE) A5:2017-Broken Access Control A6:2017-Security Misconfiguration A7:2017-Cross-Site Scripting (XSS) A8:2017-Insecure Deserialization A9:2017-Using Components with Known Vulnerabilities A10:2017-Insufficient Logging&Monitoring Please Contact me anytime if you are really looking forward to a quality and world-class work delivered to you. It will be a pleasure to work with you. See you online and have a great day! Warm regards, Shofiur
$250 USD en 2 días
4,9 (18 comentarios)
5,3
5,3
Avatar del usuario
Hello! I am very interested in your post project. i am Express JS, Javascript, node.js, NoSQL Couch & Mongo, Web Security expert. i am really looking for this kind of project since i have rich experience on it. I think this project is very suitable for me and i am sure i can give you good result . If you award me for your project, you will get good result . please call me Dmitrii. looking forward to work with you. thanks regards
$155 USD en 3 días
4,6 (35 comentarios)
5,6
5,6
Avatar del usuario
>> SENTRY Hello, I am a Node.js security expert and can definitely help you out to apply all security suggestions to run a production server. I have referred your job description along with the articles. Also, I am experienced with MongoDB, AWS. As I have total 10+ years of experience with Node.js, React.js, AngularJS, JavaScript, PHP, Ruby on Rails, PostgreSQL, AWS, Heroku, AJAX, Bootstrap, Git, HTML, CSS, etc... technologies and based on my experience and expertise, I assure you that all your requirements will be FULFILLED with a satisfactory OUTCOME. I have worked on many enterprise-level Node.js projects with a high level of my client's satisfaction. Also, I can give you a demo over the call or during an interview. And I am really interested to discuss your project requirements thoroughly. Please open the message box to go ahead. Kindly let me know if you have any query or concern. Waiting for your response. Thanks!
$250 USD en 3 días
5,0 (5 comentarios)
4,1
4,1
Avatar del usuario
Dear Sir, Greeting from my side, I would like to apply for this job, and I will make it as per your requirement, as described in your Job details. As a young, dynamic, experience and talented team of software developer I would like to apply for this job, and we will deliver it as per your requirement. When you would like to discuss our next steps. Best quality and on time work is our guarantee. With warm regards & Thanks, Ashok Rathod Mxicoders
$250 USD en 7 días
5,0 (5 comentarios)
4,3
4,3
Avatar del usuario
SENTRY I'm interested in your project. Please send me a message so that we can discuss more. Thanks & Regards, Mohammad https://www.freelancer.com/u/LinuxGun
$150 USD en 0 día
5,0 (3 comentarios)
3,4
3,4
Avatar del usuario
Hi Dear, Really love to see your needful need here in Freelancer. As handled projects from scratch to floors were build teams and plans for startup development environments. I’m always keen for a long term handshake which makes me loud and clear as regards of my career growth. Please consider me you’re your project to build a nice relationship. Can guarantee you that you never been regret upon our business working relationship. Need a relation first rest Commercials will discussed and negotiate later as we go on. I don't wants to write generic words to get your job as I’m little strategic to think in a whole. As of my team and individual work present includes demonstrable ability to deliver projects on time, with high quality, and within budget. Please feel free for a quick chat to clear the relationship more. Advance thanks and regards
$155 USD en 3 días
0,0 (0 comentarios)
0,0
0,0
Avatar del usuario
Hello Sir, I have experience in nodejs application, i can add security module as you want I also know about Mongo and Mongoose. I can complete your task as per your requirement. Thanks
$166 USD en 3 días
0,0 (0 comentarios)
0,0
0,0

Sobre este cliente

Bandera de UNITED STATES
San Diego, United States
5,0
23
Forma de pago verificada
Miembro desde jun 8, 2016

Verificación del cliente

¡Gracias! Te hemos enviado un enlace para reclamar tu crédito gratuito.
Algo salió mal al enviar tu correo electrónico. Por favor, intenta de nuevo.
Usuarios registrados Total de empleos publicados
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Cargando visualización previa
Permiso concedido para Geolocalización.
Tu sesión de acceso ha expirado y has sido desconectado. Por favor, inica sesión nuevamente.