Web Application Penetration Testing

Find the holes before someone else does.

We test your web applications and APIs the way an attacker would: manually, across the full range of modern vulnerability classes. Then we give you a report your developers can act on.

Request a test

What you get

Manual testing

Automated scanners miss logic flaws and chained attacks. We test by hand, with tooling where it helps.

Clear report

Each finding with severity, proof of concept, business impact and a specific fix. Plus a one-page executive summary.

Free retest

Once you've fixed the findings, we retest them and confirm they're closed.

OWASP-aligned

Every area we test is mapped to the OWASP Top 10, so results slot into your compliance and audit work.

Testing coverage

The vulnerability classes we test for, grouped by where the attack happens. OWASP Top 10 (2021) category shown on the right.

Server-side

AreaWhat we checkOWASP
SQL injectionUntrusted input reaching database queries, leading to data theft, login bypass or data tampering.A03 Injection
NoSQL injectionQuery and operator injection in document databases such as MongoDB.A03 Injection
OS command injectionInput passed to system commands, leading to code execution on the server.A03 Injection
Server-side template injectionUser input evaluated by template engines, often leading to remote code execution.A03 Injection
XXE injectionXML parsers that load external entities, exposing files and internal networks.A05 Misconfiguration
Path traversalReading or writing files outside the intended directory.A01 Access Control
Access controlHorizontal and vertical privilege escalation, IDOR, missing function-level checks.A01 Access Control
AuthenticationPassword policy, brute-force protection, multi-factor bypass, password reset flaws.A07 Auth Failures
Business logicFlaws in how the application's rules are enforced, such as pricing, workflows and limits.A04 Insecure Design
Race conditionsConcurrent requests that bypass limits, double-spend or corrupt state.A04 Insecure Design
File uploadUploads that allow executable files, overwrite content or bypass validation.A04 Insecure Design
Information disclosureError messages, debug output, source files and metadata leaking sensitive data.A05 Misconfiguration
Server-side request forgeryMaking the server send requests to internal systems or cloud metadata services.A10 SSRF
API testingUndocumented endpoints, mass assignment, parameter pollution, broken object-level authorisation.A01 Access Control
Web cache deceptionTricking caches into storing and serving private user content.A05 Misconfiguration

Client-side

AreaWhat we checkOWASP
Cross-site scripting (XSS)Reflected, stored and DOM-based script injection into pages other users see.A03 Injection
Cross-site request forgeryForcing a logged-in user's browser to perform unwanted actions.A01 Access Control
CORSOver-permissive cross-origin policies that expose data to other sites.A05 Misconfiguration
ClickjackingHidden framing that tricks users into clicking on your interface.A05 Misconfiguration
DOM-based vulnerabilitiesUnsafe client-side JavaScript sources and sinks, including open redirects.A03 Injection
WebSocketsInput handling and cross-site hijacking of WebSocket connections.A01 Access Control

Protocols & integrations

AreaWhat we checkOWASP
Web LLM attacksPrompt injection, excessive agency and data leakage in AI chatbots and LLM integrations.A03 Injection
GraphQL APIsIntrospection exposure, batching abuse, authorisation gaps in resolvers.A01 Access Control
OAuth authenticationFlawed OAuth and OpenID Connect flows leading to account takeover.A07 Auth Failures
JWT attacksWeak signing, algorithm confusion and missing validation of JSON Web Tokens.A02 Crypto Failures
HTTP request smugglingFront-end and back-end servers disagreeing on where requests end.A05 Misconfiguration
HTTP Host header attacksPassword reset poisoning, routing abuse and cache poisoning via the Host header.A05 Misconfiguration
Web cache poisoningGetting a cache to serve malicious responses to other users.A05 Misconfiguration
Prototype pollutionJavaScript object pollution, client-side and server-side (Node.js).A03 Injection

Rules of engagement

We only test systems you own or are authorised to test. Every engagement starts with a written scope, agreed testing windows and named contacts. Findings stay confidential and are shared only with you.

Request a security test

Tell us what you want tested: the URL, the type of application and any deadline. We'll send a scope and quote.

info@xano.it