Offensive Security
Web Application Penetration Testing
We go through your application by hand, as each kind of user, and try to get at things that user should not reach. You get back what worked, and what to change.
Coverage
What we test
The final scope follows your application and its risks. These are the areas this assessment normally covers.
-
Manual testing
The application is worked through by hand, role by role and feature by feature, rather than handed to a scanner and reported on.
-
Authentication and authorisation testing
Login, session establishment, multi-factor flows where they exist, and whether each role can reach only what it is supposed to reach.
-
Input validation and injection testing
SQL, command, template and similar injection classes, and how the application behaves on input it did not expect.
-
Session and security control testing
Session lifetime and invalidation, cookie attributes, CSRF defences, and the security headers the application relies on.
-
Business logic testing
Whether the application's own rules on limits, sequences, prices and ownership hold when a user does not follow the intended path.
-
Client-side security testing
Cross-site scripting, DOM-based issues, client-side access control, and data the front end exposes that the back end assumes is hidden.
Next step
Scope the right amount of testing
You do not need to choose a service before contacting us. Describe the application and we will map the work to it.
Ask about web application testing
Send a paragraph about what you built. We will tell you what is worth testing.