Real Attacks on Your Web App
Web Application Penetration Testing
We test your web application by hand, the way someone trying to break in would. Automated scanners find the noise; we find the auth bypass, the broken access control and the injection that a scanner walks straight past.
See the engagement path, 6 phasesSee the full VAPT service index
Overview
A web application VAPT looks at everything an attacker can reach through the browser and the requests behind it. We work through authentication, session handling, access control, input handling and business logic, mapping how flaws chain together into real impact. You get an accurate picture of what a motivated attacker could do to your users and your data, not a list of theoretical warnings.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Web Application engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise. Activities: Confirm target URLs and environments; Provision test accounts for each role; Agree off-limits actions and data; Set testing windows and escalation contacts. Hands over Signed Rules of Engagement. Phase 2, Reconnaissance and Mapping. We map every page, endpoint, parameter and role, and fingerprint the stack so we know the surface before we start pushing on it. Activities: Spider the app across every role; Enumerate endpoints and parameters; Fingerprint the stack and third-party components; Map roles to the features they reach. Hands over Attack Surface Map. Phase 3, Vulnerability Discovery. We combine manual review with tooling to surface injection, access-control, session and configuration issues across the app. Activities: Test input handling for injection flaws; Probe authentication and session management; Check access control across roles and objects; Review configuration and security headers. Hands over Candidate Finding List. Phase 4, Manual Exploitation. We prove each finding by exploiting it in a controlled way, confirming impact and ruling out false positives. Activities: Build a working exploit per finding; Confirm impact in a controlled way; Discard false positives; Capture proof-of-concept evidence. Hands over Proven Findings with Evidence. Phase 5, Post-Exploitation and Impact. We show how far a flaw reaches: what data it exposes, which accounts it touches and how issues chain into a bigger compromise. Activities: Chain findings into a larger compromise; Map exposed data and reachable accounts; Assess business impact of each chain; Rank issues by real-world risk. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a clear report with proof of concept and fixes, and once you remediate we retest to confirm each issue is closed. Activities: Write findings, impact and remediation; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Rules of Engagement
We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise.
What Happens In This Phase
- Confirm target URLs and environments
- Provision test accounts for each role
- Agree off-limits actions and data
- Set testing windows and escalation contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
Phase 01 Scoping and Rules of Engagement
We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise.
What Happens In This Phase
- Confirm target URLs and environments
- Provision test accounts for each role
- Agree off-limits actions and data
- Set testing windows and escalation contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
- 01
Scoping and Rules of Engagement
We agree the targets, test accounts, roles and any off-limits actions, then set testing windows and contacts so nothing takes your team by surprise.
OutputSigned Rules of EngagementActivities
- Confirm target URLs and environments
- Provision test accounts for each role
- Agree off-limits actions and data
- Set testing windows and escalation contacts
- 02
Reconnaissance and Mapping
We map every page, endpoint, parameter and role, and fingerprint the stack so we know the surface before we start pushing on it.
OutputAttack Surface MapActivities
- Spider the app across every role
- Enumerate endpoints and parameters
- Fingerprint the stack and third-party components
- Map roles to the features they reach
- 03
Vulnerability Discovery
We combine manual review with tooling to surface injection, access-control, session and configuration issues across the app.
OutputCandidate Finding ListActivities
- Test input handling for injection flaws
- Probe authentication and session management
- Check access control across roles and objects
- Review configuration and security headers
- 04
Manual Exploitation
We prove each finding by exploiting it in a controlled way, confirming impact and ruling out false positives.
OutputProven Findings with EvidenceActivities
- Build a working exploit per finding
- Confirm impact in a controlled way
- Discard false positives
- Capture proof-of-concept evidence
- 05
Post-Exploitation and Impact
We show how far a flaw reaches: what data it exposes, which accounts it touches and how issues chain into a bigger compromise.
OutputImpact and Risk AssessmentActivities
- Chain findings into a larger compromise
- Map exposed data and reachable accounts
- Assess business impact of each chain
- Rank issues by real-world risk
- 06
Reporting and Verified Retest
You get a clear report with proof of concept and fixes, and once you remediate we retest to confirm each issue is closed.
OutputFinal Report and Verified RetestActivities
- Write findings, impact and remediation
- Produce an executive summary
- Walk your team through the results
- Retest fixes and confirm closure
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Web Application scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Burp Suite Professional, OWASP ZAP, Nuclei, sqlmap, ffuf, Nikto, Nmap, wpscan. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: OWASP Web Security Testing Guide (WSTG), OWASP Top 10, OWASP ASVS, PTES, NIST SP 800-115, CVSS v4.0.
What We Run
8 tools
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- OWASP
- OWASP
- OWASP
- PTES
Deliverables
What You Receive
- Findings report with proof of concept
- Executive summary
- Remediation guidance
- Verified retest report
- Attestation letter
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Will testing affect our live application?
We prefer a staging environment that mirrors production. When you need production tested, we work in agreed windows and avoid destructive actions, and we keep a line open to your team throughout.
Do you test authenticated areas?
Yes. We test as an anonymous user and with the roles you provide, because most serious access-control and business-logic flaws only appear once you are logged in.
How long does a web application test take?
Most applications take one to two weeks depending on the number of roles, features and endpoints. We confirm the timeline once scoping is done.
Keep Moving Through VAPT
Service 1 of 7 in this practice area
Practice Area
More in VAPT
- Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- Thick Client ApplicationDesktop app testing across binary, traffic and backend
- Network InfrastructureExternal and internal network testing with lateral movement
- IoT and EmbeddedDevice testing across firmware, hardware and radio
- CloudConfiguration and IAM testing across AWS, Azure and GCP