Offensive Security

Authentication & Authorisation Testing

Can one customer see another customer's data? Can a normal user do an admin's job? This is the shorter engagement for when that is the question that keeps you up.

Coverage

What we test

The final scope follows your application and its risks. These are the areas this assessment normally covers.

  • Broken access control

    Endpoints, objects and functions reachable by users who should not reach them, both across accounts and up through roles.

  • Privilege escalation

    Paths from a low-privilege account to a higher-privilege one, including through features built for administrators.

  • Session management

    Issue, renewal, expiry and concurrent sessions, and what a logout actually invalidates.

  • Account recovery

    Password reset, email change and recovery flows, which are routinely weaker than the login they can bypass.

  • Role separation

    Whether roles are enforced on the server or only reflected in what the interface chooses to render.

Next step

Scope the right amount of testing

You do not need to choose a service before contacting us. Describe the application and we will map the work to it.

How testing worksAssessments and pricing

Ask about authentication & authorisation

Send a paragraph about what you built. We will tell you what is worth testing.