Offensive Security

Web Application Penetration Testing

We go through your application by hand, as each kind of user, and try to get at things that user should not reach. You get back what worked, and what to change.

Coverage

What we test

The final scope follows your application and its risks. These are the areas this assessment normally covers.

  • Manual testing

    The application is worked through by hand, role by role and feature by feature, rather than handed to a scanner and reported on.

  • Authentication and authorisation testing

    Login, session establishment, multi-factor flows where they exist, and whether each role can reach only what it is supposed to reach.

  • Input validation and injection testing

    SQL, command, template and similar injection classes, and how the application behaves on input it did not expect.

  • Session and security control testing

    Session lifetime and invalidation, cookie attributes, CSRF defences, and the security headers the application relies on.

  • Business logic testing

    Whether the application's own rules on limits, sequences, prices and ownership hold when a user does not follow the intended path.

  • Client-side security testing

    Cross-site scripting, DOM-based issues, client-side access control, and data the front end exposes that the back end assumes is hidden.

Next step

Scope the right amount of testing

You do not need to choose a service before contacting us. Describe the application and we will map the work to it.

How testing worksAssessments and pricing

Ask about web application testing

Send a paragraph about what you built. We will tell you what is worth testing.