API security testing
Testing of REST, GraphQL, gRPC and WebSocket interfaces for broken authorisation, data exposure and abuse of business flows.
Application security
Manual testing of web applications for flaws in authentication, access control, business logic and data handling.
Application security
Most breaches of web applications do not start with an exotic exploit. They start with a request the application should have refused: an invoice of another customer, a price changed in transit, a password reset that trusts the wrong header. Scanners miss these flaws because they do not know what the application is for.
We test as authenticated users of every role, map what each role can reach and then try to cross every boundary between them. Automated tools cover the known classes. The time of the specialists goes into logic, access control and chains of small weaknesses that add up to a compromise.
01Scope
02Approach
We build a map of roles, functions, data flows and entry points, including the parts of the application that the interface does not link to.
Scanners and our own tooling cover known vulnerability classes, so that manual time is not spent on what a machine can find.
Every function is tested by hand against the relevant OWASP WSTG test cases, with the emphasis on access control and business logic.
A weakness is exploited to the agreed depth to prove real impact and is combined with others where that leads further.
03
04
05Standards
Test cases for web applications and APIs.
OWASP Foundation
Requirements an application is verified against.
OWASP Foundation
The most critical risks of web applications; a minimum, not a method.
OWASP Foundation
PTESv1.0
Phases of an engagement, from pre-engagement to reporting.
PTES Team
Severity score and vector of every finding.
FIRST
Class of weakness behind every finding.
The MITRE Corporation
06Questions
Grey box by default: we work with accounts and documentation, because that finds the most in the time available. Black box is appropriate when you want to measure what an outsider achieves with no information. White box adds the source code and is described under secure code review.
We prefer an environment that matches production. Where only production exists, we agree test windows, avoid destructive actions and work with our own test data.
A scanner finds known patterns in single requests. It does not know that one customer must not see the orders of another, or that a discount must not be applied twice. Those flaws are found by people who understand the application.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.