← All services
Penetration testing service
Web Application Penetration Test
Manual testing of an authenticated web application against the OWASP ASVS, looking for the logic and access-control flaws that scanners do not find.
What the test covers
- Authentication, session handling and password reset flows
- Authorisation testing across every role, including horizontal and vertical privilege escalation
- Business logic abuse — workflow bypass, race conditions, price and quantity tampering
- Injection classes: SQL, NoSQL, command, template and deserialisation
- Server-side request forgery and file upload handling
- Client-side issues: XSS, CSRF, clickjacking, DOM sinks
- Configuration and header review against the deployed environment
Deliverables
- Executive summary written for a non-technical reader
- CVSS-scored findings with reproduction steps and evidence
- Prioritised remediation roadmap
- Technical annexure of everything tested, including what came back clean
- One retest round with a signed closure letter
Out of scope
- Denial-of-service and volumetric load testing
- Social engineering of your staff, unless separately agreed in writing
- Physical security
- Third-party services you do not own or control