Offensive Security
Authentication & Authorisation Testing
Can one customer see another customer's data? Can a normal user do an admin's job? This is the shorter engagement for when that is the question that keeps you up.
Coverage
What we test
The final scope follows your application and its risks. These are the areas this assessment normally covers.
-
Broken access control
Endpoints, objects and functions reachable by users who should not reach them, both across accounts and up through roles.
-
Privilege escalation
Paths from a low-privilege account to a higher-privilege one, including through features built for administrators.
-
Session management
Issue, renewal, expiry and concurrent sessions, and what a logout actually invalidates.
-
Account recovery
Password reset, email change and recovery flows, which are routinely weaker than the login they can bypass.
-
Role separation
Whether roles are enforced on the server or only reflected in what the interface chooses to render.
Next step
Scope the right amount of testing
You do not need to choose a service before contacting us. Describe the application and we will map the work to it.
Ask about authentication & authorisation
Send a paragraph about what you built. We will tell you what is worth testing.