Web application testing
Still where most of the ways in are.
Manual testing of the application as a logged-in user, then as a user who should not be able to do what they are doing. Scanners find the known problems; the logic flaws that matter are found by reading the application the way its builders did not.
What we look at
- Authentication, session and account management
- Access control across roles, accounts and objects
- Business logic, workflows and state
- Injection, deserialisation, file handling
- Front-end and third-party components
What you receive
- Proof of exploit wherever it is safe to produce one
- An executive summary and full technical detail
- Fix guidance with the specific code path where we can
- Retest once fixed
Frameworks we map to OWASP Web Security Testing Guide, OWASP ASVS, OWASP Top 10