Skip to content

Home Expertise / Penetration testing

PEN / PEN-03

Web application penetration testing

Testing browser-based applications for weaknesses, particularly in authentication, authorisation and business workflows.

WHEN IT HELPS

A focused response
to a defined need.

Software vendor, product owner or CIO; launch, major release or a portal handling sensitive data.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Critical workflows and roles
  • session and access controls
  • manual testing supported by tools, using grey-box or white-box access as agreed

Deliverables

  • Contextualised findings
  • evidence using test accounts
  • remediation tickets understandable to developers

Acceptance evidence

Covered and uncovered scenarios are listed; findings distinguish technical severity from business impact.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Which roles and workflows? Is there a representative staging environment? Are code and specifications included?

IMPORTANT BOUNDARIES

An automated scan alone is not a complete penetration test; a Top 10 list is not exhaustive coverage.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

An invoice portal must isolate each customer’s documents. Project: test account boundaries with synthetic data. Target outcome: fix cross-account access or demonstrate control over executed scenarios, followed by a retest.

Scenario 02

An online shop restricts special discounts to selected profiles. Project: test purchase-workflow logic. Target outcome: server-side enforcement of business rules; load testing remains out of scope.

Technology and reference context

OWASP WSTG and ASVS; testing proxy and dedicated accounts, with reference versions specified.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.