Web application penetration testing
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.
Application security
An API exposes the business logic directly, without the interface that used to hide it. Identifiers are in the open, fields that the client never shows are still accepted by the server, and every endpoint is one request away from anyone with a token.
We work from the specification where there is one and rebuild it from traffic where there is not. Every endpoint is called as every role, with the identifiers of other users and tenants, with fields it should not accept and in an order the workflow does not expect.
01Scope
02Approach
We compare the specification with real traffic and with the mobile and web clients, and list the endpoints that exist but are not documented.
Each operation is called with the credentials of each role against objects of other users and tenants. The result is a matrix of what is allowed against what should be.
We send fields, types and structures the schema does not expect: extra properties, nested queries, oversized batches, conflicting content types.
Operations are replayed, reordered and run in parallel to find race conditions and flows that can be automated to the detriment of the business.
03
04
05Standards
The most critical risks of APIs.
OWASP Foundation
Test cases for web applications and APIs.
OWASP Foundation
Requirements an application is verified against.
OWASP Foundation
Severity score and vector of every finding.
FIRST
Class of weakness behind every finding.
The MITRE Corporation
06Questions
Yes. We rebuild the interface from the traffic of your clients and from the behaviour of the server. The missing documentation is itself a finding, and the inventory we build is part of the report.
The target is the interface between systems, not the pages a person sees. The work concentrates on authorisation of every object and operation, on schemas and on automated abuse, which is where API breaches come from.
Yes, from the network position you define: from the internet, from a partner network or from inside the cluster. Internal APIs often trust their callers more than they should.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.