Skip to content
AttackVector

Can this application be turned against its users?

Web application test

A web application penetration test is a manual security assessment of one application and its APIs, covering authentication, authorization, business logic, and data handling. It finds and proves the flaws that automated scanners cannot, such as broken access control between users and tenants.

Point in timeTargets: TechnologyTypically 1 to 3 weeks depending on application size and roles

What you get

  • Confirmed vulnerabilities with working proof of concept
  • Authorization and logic flaws, not just scanner output
  • Developer-ready remediation guidance

Overview

A focused assessment of a single application: authentication, authorization, business logic, injection, and the APIs behind the interface. We combine manual testing with tooling so that logic flaws automated scanners miss are found and demonstrated.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • One web application, including all user roles agreed in scoping
  • REST, GraphQL, or SOAP APIs used by the application
  • Authentication, session management, and password flows
  • Authorization between users, roles, and tenants
  • Business logic and workflow abuse
  • Input handling: injection, file upload, deserialization
  • Client-side controls and third-party integrations

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. Application mapping

    We walk every role and workflow to build a full map of endpoints, parameters, and trust boundaries.

  2. Authentication and session

    Login, recovery, MFA, and session handling are tested for takeover and bypass.

  3. Authorization

    Every function and object is tested across roles and tenants to find horizontal and vertical access flaws.

  4. Input and logic

    Injection, upload, and deserialization testing alongside business logic abuse such as price, quantity, and state manipulation.

  5. Verification and reporting

    Each finding is reproduced with a working proof of concept and paired with developer-ready remediation.

Deliverables

  • Executive summary for product and security leadership
  • Findings with reproduction steps, requests, and responses
  • Severity and CVSS score for each finding
  • OWASP Web Security Testing Guide coverage checklist
  • Developer remediation guidance with code-level pointers
  • Attestation letter for customers and auditors
  • One retest of remediated findings

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · Web application test · Technical findingsIllustrative excerpt
HighFinding 1 of 19

Password reset flow allows account takeover

Severity
High
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

An attacker who knows a victim's email address could reset the victim's password without access to their inbox, taking over any account including administrators.

Evidence

Reset token accepted for a different account than the one it was issued to, demonstrated against two test accounts created for the engagement.

Screenshot and request/response evidence appear here

Remediation

Bind reset tokens to the account and session they were issued for, make tokens single use with a short expiry, and add rate limiting and alerting on reset attempts.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 1 to 3 weeks depending on application size and roles

What affects it

A small application with two roles takes about a week. Multi-tenant platforms with many roles and APIs take longer. Test credentials for each role should be ready on day one.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001, NYDFS.

See the full requirement mapping

Frequently asked questions

How long does a web application test take?

Typically one to three weeks. The main drivers are the number of user roles, the size of the API surface, and how much business logic the application contains.

Do you test with source code?

Most tests are grey box: we use accounts for each role but not code. Code-assisted testing is available and usually finds deeper issues in the same time.

Is a retest included?

Yes. One retest of remediated findings is included so your report and attestation reflect the fixed state.

How is this different from an external penetration test?

An external test covers your whole perimeter at network depth. A web application test goes deep on one application, including logic and authorization flaws that only appear when you use the product as a real user would.

Do you follow OWASP?

Yes. Coverage is mapped to the OWASP Web Security Testing Guide and the OWASP Top 10, and the report includes the coverage checklist.

Ready to scope a web application test?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.