Penetration testing
We attack your running application the way a real attacker would: with automated tools, by hand and with an eye for logic flaws.
We act as an attacker from the outside. Your running test system is attacked manually and with automated tools, to find its security issues the way a real attacker would.
How we work
-
Understand
We get to know your application before we attack it: features, roles, interfaces and the data that needs protecting.
-
Automated
Scanners and our own tools map the attack surface and cover known classes of bugs broadly.
AI-assisted -
Manual
The important findings are made by hand: logic flaws, bypassed permission checks, attacks chained over several steps.
-
Verify
Every finding is proven and documented so you can reproduce it.
AI-assisted
What we attack
We test web applications, APIs and mobile apps. The framework is the OWASP Web Security Testing Guide (WSTG), the established standard for security testing of web applications. It divides active testing into twelve areas:
Information gathering: attack surface, entry points and the technology in use. Where it makes sense, we start every penetration test with an infrastructure analysis: open services, TLS, DNS and everything that can be found out about you publicly
Configuration and deployment: server and platform, HTTP methods, security headers, forgotten files and admin interfaces
Identity management: roles, registration, account provisioning, guessable user names
Authentication: login, password policy, password reset, multi-factor, brute-force protection
Authorisation: permission checks, privilege escalation, direct access to other users' objects (IDOR), path traversal
Session management: cookies, session fixation, logout and timeout, CSRF
Injection: SQL, command and template injection, cross-site scripting, SSRF
Error handling: error messages and stack traces that reveal internals
Cryptography: TLS, weak algorithms, sensitive data in plain text
Business logic: bypassed workflows, manipulated values, limits and race conditions
Client side: DOM-based cross-site scripting, clickjacking, CORS, web messaging
APIs: REST and GraphQL, permission checks on every endpoint
The risks of the OWASP Top 10 are all covered. To us, though, the WSTG is a framework, not a checklist to tick off: the most important findings are made where an application has rules of its own.
Penetration testing and source code analysis complement each other: the test from the outside shows what an attacker actually achieves, the look at the code finds what stays hidden from the outside. On request we combine both.
Result
At the end there is always a report. Either brief and to the point, so that as much time as possible goes into the actual analysis, or a detailed report with a description of every vulnerability, a risk assessment and concrete remediation advice. Follow-up questions included.