Application security

Web Application Penetration Testing

Manual, authenticated testing of your web applications — the access-control, session and business-logic flaws that automated scanners never reach.

Overview

What it covers

A web application is where most organizations concentrate their risk: it is public, it holds the data, and it trusts input from anyone with a browser. We test it the way an attacker would, with valid credentials for every role, chaining small weaknesses into the kind of compromise that ends in someone else’s data. Testing follows the OWASP Web Security Testing Guide and maps to the Application Security Verification Standard.

Scope

What we test

Every engagement is scoped to your environment, but these are the areas a Web Application test engagement covers.

Broken access control

Horizontal and vertical authorization — whether one user can reach another’s data or an admin function.

Injection and input handling

SQL, NoSQL, command and template injection, plus the SSRF and deserialization flaws behind modern breaches.

Authentication and sessions

Login, MFA, password reset and session lifecycle, including tokens that outlive a credential change.

Business logic

Abuse of the workflows unique to your app — pricing, checkout, approvals — that no signature detects.

Client-side and API

The JavaScript front end and the API it calls, tested together the way they are actually attacked.

Methodology

How the engagement runs

The same defensible sequence every time.

Scoping and a fixed-price quote, reconnaissance and threat modeling, manual exploitation with same-day escalation of critical findings, a report your engineers and auditors can both use, and a free retest once fixes ship.

1
Scoping & rules of engagement
Fixed-price quote in ~1 hour
2
Reconnaissance & threat modeling
Prioritize the paths that matter
3
Manual exploitation
Same-day critical escalation
4
Reporting
CVSS v3.1, reproduction, control mapping
5
Remediation retest
Included in the engagement
Questions

Web Application test, answered

Do you test in production or staging?

Either, agreed in scoping. Most testing runs against a staging environment that mirrors production to remove any risk to live data; where only production exists we test with agreed limits and destructive actions out of scope.

Do you need source code?

No, though it helps. We test grey-box by default — credentials for each role but no code — which matches an attacker’s position. White-box testing with code is available where deeper assurance is needed.

Ready to scope a Web Application test?

A 30-minute call gets you a fixed price and a start date, usually within the hour.