Skip to content
MD-5

// Web App Pentest

Web Application Penetration Testing

An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.

Overview

Automated scanners are good at spotting missing headers and outdated libraries. They are bad at noticing that one customer can read another customer’s invoices, that a discount code can be applied twice, or that a “viewer” role can call an admin-only endpoint.

A web application penetration test puts an experienced attacker in front of your app, logged in as each of your user roles, to find the flaws that actually lead to breaches, then shows your developers exactly how to fix them.

Who this is for

  • SaaS startups preparing for an enterprise security review or SOC 2 audit
  • E-commerce and marketplace sites handling payments or personal data
  • Teams shipping a major release, new auth system, or multi-tenant feature

What gets tested

Access control & authorization

  • Horizontal and vertical privilege escalation between roles and tenants
  • Insecure direct object references (IDOR) on every object type
  • Admin and internal functions reachable by ordinary users

Authentication & sessions

  • Login, registration, password reset and MFA flows
  • Session handling, token lifetime and logout behavior
  • Account enumeration and brute-force protections

Injection & input handling

  • SQL, NoSQL and command injection
  • Cross-site scripting (reflected, stored and DOM-based)
  • Server-side request forgery (SSRF) and file upload handling

Business logic & configuration

  • Workflow bypasses, race conditions and pricing/limit abuse
  • Security headers, CORS, cookies and TLS configuration
  • Sensitive data exposure in responses, errors and client-side code

What you receive

  • Executive summary written for non-technical stakeholders
  • Every finding with severity (CVSS), evidence, reproduction steps and a specific fix
  • Live readout call to walk your team through the results
  • Retest of fixed findings and an updated report
  • Letter of attestation you can share with customers and auditors

Standards followed

  • OWASP Web Security Testing Guide (WSTG)
  • OWASP Top 10
  • OWASP ASVS
  • CVSS v3.1 / v4.0

Read the full testing methodology.

// Process

How the engagement runs

  1. 01 Day 0

    Scope

    A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.

  2. 02 Days 1 to 10

    Test

    Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.

  3. 03 +3 days

    Report

    A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.

  4. 04 When you’re ready

    Retest

    Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.

// FAQ

Web App Pentest questions

Do you test in production or staging?

Either. Staging is preferred when it mirrors production closely. When testing production, we agree testing windows with you, avoid destructive actions, and use dedicated test accounts so real customer data isn’t touched.

Do you need test accounts?

Yes. Ideally two accounts per user role (so access between users can be tested), plus any seed data needed to exercise the main features. Unauthenticated-only testing is possible, but finds far less.

Is this a white-box or black-box test?

Grey-box by default: authenticated access plus a short walkthrough of the app. That gives the best coverage for the budget. Source code review can be added for critical areas.

Will the report satisfy our customer’s security questionnaire?

That’s one of its main uses. The report plus a letter of attestation covers the standard “have you had an independent penetration test in the last 12 months?” question.

// Further reading

// Also available

Other services

API Pentest

Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.

Network Pentest

External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.

Vulnerability Assessment

A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.