Skip to content
normSight — Cyber Security

Solutions

Web Application Penetration Testing

Web application penetration testing is the identification of security flaws in an application's source code, session management, authorisation and data layer through authorised exploitation by a specialist.

Penetration tests are carried out through a simulation performed by an authorised person in order to identify security vulnerabilities within an internet-facing system. Web application penetration testing, one of these assessments, is applied by deliberately penetrating a web application in order to detect security flaws.

The test makes it possible to identify these dangers where a web application in use contains a security vulnerability, holds errors or faces threats. The available types of web application penetration testing include manual and automated testing. As the selected test is applied, security weaknesses are identified within the web application and its components — that is, within the source code, database, services and servers. The attacks and the environments that could be used are then examined from an attacker’s point of view.

Web application penetration testing ultimately enables security vulnerabilities and threats to be identified, remediation methods to be sought, and those methods to be applied. The aim is to identify threats and flaws through this work and then to reduce or eliminate them.

Carried out by an expert team, this is one of the most important penetration testing services today, because attackers who exploit flaws and errors can both damage your systems and cause substantial financial loss. Having this test performed professionally every six months, or at least annually, and eliminating the vulnerabilities it uncovers as soon as possible, is of clear benefit to the organisation.

Frequently Asked Questions

Do I need to provide source code access for the test?

It is not required, but providing it increases the depth of the test. In a black-box test the surface an attacker sees is assessed; in a white-box test, where code access is given, business logic flaws and authorisation defects are found with far greater accuracy.

Is the test performed against the live environment?

Preferably it is performed against a test environment that mirrors production. Where the live environment is unavoidable, attempts that modify data are restricted and the work is moved outside business hours.

Which vulnerabilities are in scope?

Injection flaws, authentication and session management defects, authorisation bypass (IDOR), server-side request forgery, file upload flaws, business logic errors and configuration weaknesses are assessed, with the OWASP Top 10 as a baseline.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.