Web penetration testing: web application security assessment
Your web application is the gateway to your data, your customers and your business. We assess its security the way a real attacker would, covering everything from the OWASP Top 10 to the specific vulnerabilities of your technology stack.
Web applications are the most exploited attack vector
More than 80% of successful cyberattacks exploit vulnerabilities in web applications. SQL injection, XSS, sensitive data exposure, weak authentication, inadequate access control... Most of these flaws are silent: your app works perfectly while a back door stays open. Web pentesting finds them and closes them before someone else does.
What we cover in a web pentest
- OWASP Top 10: SQL injection, XSS, SSRF, IDOR, broken auth, insecure deserialization...
- Business logic: bypassing purchase flows, privilege escalation, data manipulation
- Authentication and session management: tokens, cookies, 2FA, password resets
- Access control: BOLA/IDOR, horizontal and vertical access to resources
- Server configuration: HTTP headers, TLS, CORS, CSP
- Exposure of sensitive information in responses, errors and metadata
Web pentesting methodology
- Reconnaissance and mapping: We identify the attack surface: subdomains, technologies, exposed endpoints, framework versions.
- Authentication analysis: We assess the login flow, session management, password policies and 2FA mechanisms.
- Manual logic testing: We review critical business flows: purchases, user roles, permissions, state changes.
- Vulnerability exploitation: We confirm and exploit each finding in a controlled way to measure its real impact.
- Documentation and delivery: Each vulnerability includes a description, evidence (screenshots, requests/responses), CVSS and steps to reproduce it.
Deliverables
- Executive report: overall exposure, business risk, action priorities
- Technical report: each vulnerability with PoC, CVSS and recommended fix
- OWASP and CVSSv3 classification of all findings
- Review meeting with the development team
- Re-test of critical vulnerabilities once remediated
What types of applications do we test?
- E-commerce with payment gateways and card data (PCI-DSS)
- B2B SaaS with multi-user access and sensitive customer data
- Corporate portals, intranets and extranets
- Management applications (ERP, CRM, HCM) exposed to the internet
- WordPress, Magento, PrestaShop and other CMS with third-party plugins
- Public or semi-public web APIs
Frequently asked questions
Do you do black, grey or white box testing?
All three. Black box simulates an external attacker with no prior information. Grey box includes standard user credentials to assess access control. White box includes access to the code and architecture and allows a more exhaustive analysis. Most clients choose grey box as a balance between realism and coverage.
Do you assess WordPress and other CMS?
Yes. WordPress is the most attacked CMS in the world precisely because of the proliferation of vulnerable plugins. We assess the core, the installed plugins, the themes, the server configuration and the admin panel access practices.
Can you sign an NDA before starting?
Always. Before you share any data about your infrastructure, we sign a confidentiality agreement.
What happens if you find critical vulnerabilities?
We notify you immediately (same day) if we find something that poses a serious and immediate risk to your business, without waiting for the full test to finish.