EspañolEnglish
Web application pentest
Where your logic breaks, not just your inputs.
A web application penetration test is manual testing of your app and its APIs: authentication and session flows, authorization, business logic, and the injection chains a scanner never reaches. REST, GraphQL, and WebSocket.
From €5,900. S, M, and larger scopes. Remote.
What a web pentest answers.
Scanners catch the flat vulnerabilities: a missing header, a known CVE, a reflected parameter. They do not understand that a normal user can read another tenant’s invoices, or that changing one field skips payment. The vulnerabilities that matter live in your application’s logic, and finding them is manual work.
Why it matters.
Authorization, done properly
IDOR and BOLA are the most common serious web flaws and the ones scanners miss entirely. We test every object and every role by hand: can this user touch that data, and what happens when they try.
Business logic
The flaws unique to your app: a negative quantity, a skipped step, a race between two requests, a coupon applied twice. No tool knows your workflow well enough to break it. We do.
Chained, not isolated
A low-severity leak plus a weak reset plus a permissive CORS policy is an account takeover. We chain findings the way an attacker would, and score them for the real impact, not the textbook one.
How we test it.
Grey box by default, because that is where the coverage is.
Grey box
Test accounts for each role. We spend time exploiting the app, not guessing at credentials, which is where the real coverage comes from.
Black box
No credentials, the anonymous attacker’s view. Useful for the exposed edge, weaker on everything behind a login.
Authenticated, per role
Every privilege level tested against every other, so horizontal and vertical authorization are actually covered.
How it runs.
Manual testing, mapped end to end.
- 01
Mapping
Every endpoint, parameter, role, and workflow. REST, GraphQL, and WebSocket surfaces enumerated in full.
- 02
Authentication and session
Login, reset, MFA, token handling, session lifecycle, and the paths around each of them.
- 03
Authorization
IDOR, BOLA, and privilege escalation, tested object by object and role by role.
- 04
Injection and server-side
SQL, NoSQL, command, template, SSRF, and deserialization, followed to real impact.
- 05
Business logic
The abuse cases specific to your workflows, the ones only a human finds.
What gets tested.
Aligned to OWASP Top 10 and ASVS, taken past the checklist.
- Authentication and session management
- Authorization: IDOR, BOLA, privilege escalation
- Business logic and workflow abuse
- Injection: SQL, NoSQL, command, template
- SSRF and server-side request handling
- Insecure deserialization
- REST, GraphQL, and WebSocket APIs
- File upload and processing
- Access control on every role
- Client-side: XSS, CSRF, CORS, clickjacking
What we usually find.
- Change one ID in the request and you read any customer’s data.
- A password reset that leaks a valid token to the wrong address.
- A checkout that accepts a negative quantity and credits the account.
- A GraphQL endpoint that exposes fields the UI never shows.
What you get.
- Findings with CVSS scores and reproduction steps
- Remediation written for your stack
- A walkthrough call with your engineers
- Retest of High and Critical findings, free within 30 days
- Mapping to OWASP Top 10 and ASVS
Web pentests start at €5,900 for the small scope; tiers scale from there. See services and pricing.
Questions.
Do you need credentials?
For real coverage, yes: test accounts for each role. Most of an application lives behind a login, and a black-box test barely touches it. We can do black box, but grey box finds far more.
Can you test in production?
Usually staging, with production-like data. Where production is the only option, we agree safe boundaries and avoid destructive actions.
REST only, or GraphQL too?
Both, and WebSocket. GraphQL in particular hides authorization flaws that never show in the UI, and it is worth testing directly.
How big is the base scope?
Small is one role and around thirty endpoints; medium is two or three roles and around eighty. Larger or multi-app scopes are quoted after scoping.
Web application
The bugs that matter are in your logic.
Thirty minutes, NDA first. You talk to the operator who tests it.
Book a free scoping callPrefer email? engagements@redghostops.com