Can this application be turned against its users?
Web application test
A web application penetration test is a manual security assessment of one application and its APIs, covering authentication, authorization, business logic, and data handling. It finds and proves the flaws that automated scanners cannot, such as broken access control between users and tenants.
What you get
- Confirmed vulnerabilities with working proof of concept
- Authorization and logic flaws, not just scanner output
- Developer-ready remediation guidance
Overview
A focused assessment of a single application: authentication, authorization, business logic, injection, and the APIs behind the interface. We combine manual testing with tooling so that logic flaws automated scanners miss are found and demonstrated.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- One web application, including all user roles agreed in scoping
- REST, GraphQL, or SOAP APIs used by the application
- Authentication, session management, and password flows
- Authorization between users, roles, and tenants
- Business logic and workflow abuse
- Input handling: injection, file upload, deserialization
- Client-side controls and third-party integrations
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Application mapping
We walk every role and workflow to build a full map of endpoints, parameters, and trust boundaries.
Authentication and session
Login, recovery, MFA, and session handling are tested for takeover and bypass.
Authorization
Every function and object is tested across roles and tenants to find horizontal and vertical access flaws.
Input and logic
Injection, upload, and deserialization testing alongside business logic abuse such as price, quantity, and state manipulation.
Verification and reporting
Each finding is reproduced with a working proof of concept and paired with developer-ready remediation.
Deliverables
- Executive summary for product and security leadership
- Findings with reproduction steps, requests, and responses
- Severity and CVSS score for each finding
- OWASP Web Security Testing Guide coverage checklist
- Developer remediation guidance with code-level pointers
- Attestation letter for customers and auditors
- One retest of remediated findings
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Password reset flow allows account takeover
- Severity
- High
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
An attacker who knows a victim's email address could reset the victim's password without access to their inbox, taking over any account including administrators.
Evidence
Reset token accepted for a different account than the one it was issued to, demonstrated against two test accounts created for the engagement.
Remediation
Bind reset tokens to the account and session they were issued for, make tokens single use with a short expiry, and add rate limiting and alerting on reset attempts.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 1 to 3 weeks depending on application size and roles
What affects it
A small application with two roles takes about a week. Multi-tenant platforms with many roles and APIs take longer. Test credentials for each role should be ready on day one.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001, NYDFS.
See the full requirement mappingFrequently asked questions
How long does a web application test take?
Typically one to three weeks. The main drivers are the number of user roles, the size of the API surface, and how much business logic the application contains.
Do you test with source code?
Most tests are grey box: we use accounts for each role but not code. Code-assisted testing is available and usually finds deeper issues in the same time.
Is a retest included?
Yes. One retest of remediated findings is included so your report and attestation reflect the fixed state.
How is this different from an external penetration test?
An external test covers your whole perimeter at network depth. A web application test goes deep on one application, including logic and authorization flaws that only appear when you use the product as a real user would.
Do you follow OWASP?
Yes. Coverage is mapped to the OWASP Web Security Testing Guide and the OWASP Top 10, and the report includes the coverage checklist.
Related
Often paired with
External penetration test
Can an outsider get in?
Your internet-facing perimeter, tested from the outside in.
Learn moreAI and LLM application test
Can this AI feature be turned against the business?
Security testing for the AI features, agents, and integrations your product now ships.
Learn moreCloud penetration test
Is our cloud configured the way we think it is?
AWS, Azure, and GCP environments assessed for the mistakes attackers look for.
Learn moreReady to scope a web application test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.