Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of VAPT7 services in this practice area

Real Attacks on Your Web App

Web Application Penetration Testing

We test your web application by hand, the way someone trying to break in would. Automated scanners find the noise; we find the auth bypass, the broken access control and the injection that a scanner walks straight past.

See the engagement path, 6 phasesSee the full VAPT service index

Overview

A web application VAPT looks at everything an attacker can reach through the browser and the requests behind it. We work through authentication, session handling, access control, input handling and business logic, mapping how flaws chain together into real impact. You get an accurate picture of what a motivated attacker could do to your users and your data, not a list of theoretical warnings.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Web Application engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise. Activities: Confirm target URLs and environments; Provision test accounts for each role; Agree off-limits actions and data; Set testing windows and escalation contacts. Hands over Signed Rules of Engagement. Phase 2, Reconnaissance and Mapping. We map every page, endpoint, parameter and role, and fingerprint the stack so we know the surface before we start pushing on it. Activities: Spider the app across every role; Enumerate endpoints and parameters; Fingerprint the stack and third-party components; Map roles to the features they reach. Hands over Attack Surface Map. Phase 3, Vulnerability Discovery. We combine manual review with tooling to surface injection, access-control, session and configuration issues across the app. Activities: Test input handling for injection flaws; Probe authentication and session management; Check access control across roles and objects; Review configuration and security headers. Hands over Candidate Finding List. Phase 4, Manual Exploitation. We prove each finding by exploiting it in a controlled way, confirming impact and ruling out false positives. Activities: Build a working exploit per finding; Confirm impact in a controlled way; Discard false positives; Capture proof-of-concept evidence. Hands over Proven Findings with Evidence. Phase 5, Post-Exploitation and Impact. We show how far a flaw reaches: what data it exposes, which accounts it touches and how issues chain into a bigger compromise. Activities: Chain findings into a larger compromise; Map exposed data and reachable accounts; Assess business impact of each chain; Rank issues by real-world risk. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a clear report with proof of concept and fixes, and once you remediate we retest to confirm each issue is closed. Activities: Write findings, impact and remediation; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Rules of Engagement

We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise.

What Happens In This Phase

  • Confirm target URLs and environments
  • Provision test accounts for each role
  • Agree off-limits actions and data
  • Set testing windows and escalation contacts

The Handover

Signed Rules of Engagement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Rules of Engagement

    We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise.

    OutputSigned Rules of Engagement

    Activities

    • Confirm target URLs and environments
    • Provision test accounts for each role
    • Agree off-limits actions and data
    • Set testing windows and escalation contacts
  2. 02

    Reconnaissance and Mapping

    We map every page, endpoint, parameter and role, and fingerprint the stack so we know the surface before we start pushing on it.

    OutputAttack Surface Map

    Activities

    • Spider the app across every role
    • Enumerate endpoints and parameters
    • Fingerprint the stack and third-party components
    • Map roles to the features they reach
  3. 03

    Vulnerability Discovery

    We combine manual review with tooling to surface injection, access-control, session and configuration issues across the app.

    OutputCandidate Finding List

    Activities

    • Test input handling for injection flaws
    • Probe authentication and session management
    • Check access control across roles and objects
    • Review configuration and security headers
  4. 04

    Manual Exploitation

    We prove each finding by exploiting it in a controlled way, confirming impact and ruling out false positives.

    OutputProven Findings with Evidence

    Activities

    • Build a working exploit per finding
    • Confirm impact in a controlled way
    • Discard false positives
    • Capture proof-of-concept evidence
  5. 05

    Post-Exploitation and Impact

    We show how far a flaw reaches: what data it exposes, which accounts it touches and how issues chain into a bigger compromise.

    OutputImpact and Risk Assessment

    Activities

    • Chain findings into a larger compromise
    • Map exposed data and reachable accounts
    • Assess business impact of each chain
    • Rank issues by real-world risk
  6. 06

    Reporting and Verified Retest

    You get a clear report with proof of concept and fixes, and once you remediate we retest to confirm each issue is closed.

    OutputFinal Report and Verified Retest

    Activities

    • Write findings, impact and remediation
    • Produce an executive summary
    • Walk your team through the results
    • Retest fixes and confirm closure

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Web Application scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Burp Suite Professional, OWASP ZAP, Nuclei, sqlmap, ffuf, Nikto, Nmap, wpscan. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: OWASP Web Security Testing Guide (WSTG), OWASP Top 10, OWASP ASVS, PTES, NIST SP 800-115, CVSS v4.0.

What We Run

8 tools

  • Burp Suite Professional
  • OWASP ZAP
  • Nuclei
  • sqlmap
  • ffuf
  • Nikto
  • Nmap
  • wpscan

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • OWASPWSTG
  • OWASPTop 10
  • OWASPASVS
  • PTES
  • NIST SP 800-115
  • CVSS v4.0
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Findings report with proof of concept
  • Executive summary
  • Remediation guidance
  • Verified retest report
  • Attestation letter

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Will testing affect our live application?

We prefer a staging environment that mirrors production. When you need production tested, we work in agreed windows and avoid destructive actions, and we keep a line open to your team throughout.

Do you test authenticated areas?

Yes. We test as an anonymous user and with the roles you provide, because most serious access-control and business-logic flaws only appear once you are logged in.

How long does a web application test take?

Most applications take one to two weeks depending on the number of roles, features and endpoints. We confirm the timeline once scoping is done.

Keep Moving Through VAPT

Service 1 of 7 in this practice area