
Web Application Penetration Testing
As long as humans are writing code, there will be bugs - some of those bugs just happen to be security vulnerabilities. Let us find them before the attackers do. Trust us to enhance your application's security and protect your critical data.
What is Web Application Penetration Testing?
Web Application and API Penetration Testing involves assessing client-side and server-side components for security flaws such as injection vulnerabilities, authentication and access control issues, insecure data storage, and logic flaws. Testing is performed in a controlled manner to identify and demonstrate potential attack paths before they can be exploited.
Our Engagement Process
T-14 days
Scoping
Our scoping process begins with a detailed consultation to understand your unique business requirements and the specific functionalities of your web applications.
A scope of testing is defined to ensure sufficient coverage, along with a testing methodology that is tailored to align with your specific security goals.
T-7 days
Get Ready for Testing
Ahead of testing, we work with you to ensure everything is ready for testing. In grey box tests, this can include setting up user accounts with varying access levels, preparing a test environment where all data flows can be executed, and sharing relevant documentation which may help with more in-depth evaluations.Start of Testing
Testing starts! Our certified penetration testers manually search for vulnerabilities to uncover security bugs deep in your code base.
Should any critical vulnerabilities be discovered, we communicate these immediately to ensure swift mitigation.
T+14 Days
Report Delivery and Debrief
Upon completion of the testing phase, we deliver a detailed report that outlines all identified vulnerabilities, accompanied by options for remediation.
A key part of our service is the debrief call, where we walk through the report together. This ensures that all findings are fully understood and that the necessary steps for remediation are clearly communicated.
Why Web Application Testing?
Identify Vulnerabilities
Without a mature application security program, non-functional requirements such as security can often be overlooked during the feature development process. Testing can help identify these hidden issues before someone else finds them.
Meet Customer Expectations
Mature buyers expect robust security measures as a standard part of any software platform. Being on the forefoot of these expectations can better demonstrate your commitment to security, enhance your reputation as a reliable software provider.
Security as a Feature
Security isn't just a necessity - it can be seen as a competitive advantage. By highlighting your commitment to regular advanced security audits you can reassure users and differentiate your product in the marketplace.
Educate Development Teams
Penetration testing can often serve as a valuable educational tool for development teams. By remediating vulnerability findings, developers gain insight into the mindset of attackers, enabling them to build more securely in the future.
Our Web Application Testing Methodology
Manual assessment forms the bulk of our penetration testing engagements:
Project Black's high-level approach to assessing web applications is adapted from Dafydd Stuttard's (Founder/CEO of Portswigger) "The Web Application Hacker's Handbook". This approach is prioritised to focus on discovery of vulnerability classes which are widely agreed upon to be the most common/critical security risks present in web applications.
Listed below are some of Project Black's most important test categories mapped against the OWASP Top 10 and SANS CWE Top 25:
Access Control Testing
Access control vulnerabilities form a large portion of easily exploitable vulnerabilities that are discovered across Project Black's testing. Testing in this phase will focus on the discovery of authentication bypass vulnerabilities and authorisation issues (lateral, vertical, and cross tenant).- A01:2021 - Broken Access Control
- A07:2021 - Identification and Authentication Failures
- CWE-862: Missing Authorization
- CWE-287: Improper Authentication
- CWE-306: Missing Authentication for Critical Function
- CWE-269: Improper Privilege Management
- CWE-863: Incorrect Authorization
- CWE-276: Incorrect Default Permissions
Input Handling
Input handling vulnerabilities are typically more difficult to exploit (thereby reducing likelihood of exploitation) however can result in significant impact to the application owner. As such they are evaluated as a part of Project Black's next testing phase.- A03:2021 - Injection
- A08:2021 - Software and Data Integrity Failures
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-20: Improper Input Validation
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-434: Unrestricted Upload of File with Dangerous Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-502: Deserialization of Untrusted Data
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-94: Improper Control of Generation of Code ('Code Injection')
Application Hosting/Security Configuration
The prevalence of PAAS consumption and dependencies on third parties' shifts testing focus in this phase to usage/configuration of said PAAS services and third-party dependencies.- A02:2021 - Cryptographic Failures
- A04:2021 - Insecure Design
- A05:2021 - Security Misconfiguration
- A06:2021 - Vulnerable and Outdated Components
- A09:2021 - Security Logging and Monitoring Failures
- CWE-798: Use of Hard-coded Credentials
Application Logic & Misc Vulnerability Classes
Finally, application specific functionality may expose the possibility for additional vulnerability classes like business logic issues.- CWE-840: Business Logic Errors
- CWE-918: Server-Side Request Forgery (SSRF)
- A10:2021 - Server-Side Request Forgery (SSRF)
- CWE-352: Cross-Site Request Forgery (CSRF)
Project Black uses the OWASP Testing Guide and internally developed tooling/methodology for specific test case guidance.
Frequently Asked Questions
What types of web applications do you test?
We test all types of web applications including traditional server-rendered apps, single-page applications (SPAs), REST and GraphQL APIs, microservices architectures, and web portals. If it runs in a browser or exposes an API, we can test it.
Should we use a staging or production environment for testing?
We recommend a staging environment that closely mirrors production - this allows us to test freely without risk to live data. If only production is available, we work with you to define testing windows and guardrails to minimise any risk.
How many user accounts do we need to set up?
For grey box testing we typically need two to three accounts: an unauthenticated session, a standard user, and an administrator or privileged role. If your application has additional distinct permission levels, providing accounts for each improves coverage.
Do you test for OWASP Top 10 vulnerabilities?
Yes. Our methodology is aligned to the OWASP Top 10 and SANS CWE Top 25, covering injection, broken access control, cryptographic failures, insecure design, security misconfiguration, and more. We go beyond automated scanning with manual testing that uncovers logic flaws automated tools miss.
How long does a web application penetration test take?
This depends on how large your application is. A typical web application test takes 5 days of testing time, depending on the number of dynamic pages, API endpoints, and user roles in scope. Larger applications or those with complex business logic may require more time.
What is code assisted testing?
Source code assisted penetration testing is something we offer to help improve test coverage without increasing time spent. By reading through how functionality is implemented, we can be much more efficient.
Ready for a Pentest Quote?
Simply fill out the form, let us know what you're looking for, and we'll reach out to you within hours!