Flaws that Scanners Miss
Manual Web Application Penetration Test, based on OWASP and OSSTMM
Flaws that Scanners Miss
Manual Web Application Penetration Test, based on OWASP and OSSTMM
The Web Application Penetration Testing service is one of the application security services (Application Security Assessment) offered by ISGroup.
Web applications are now prevalent and increasingly sophisticated, in addition to being critical for all web-based businesses.
Critical components of a web portal, an E-Commerce application, or a web platform will be analyzed.
Using manual techniques and multiple appropriate tools, the tester is able to identify both obvious and hidden vulnerabilities.
As with client/server applications, web applications generally suffer from improper client request handling and a lack of or improper validation and control by the developer.
Given the nature of web applications, they are completely exposed and accessible: this makes "security through obscurity" impossible and imposes the need for resilient application code.
Secondly, web applications process data from HTTP requests, a protocol that allows for multiple encodings and different encapsulations.
A Web Application Penetration Test represents a simulation of an attacker against a site, portal, or web application. Testing initially consists of discovering and identifying all resources exposed on the target.
In parallel, the tester performs an analysis of the business logic to verify that there are no conceptual issues.
At this point, before testing the web applications themselves, the infrastructure is checked for known and unknown vulnerabilities.
Once valid entry points are identified, we proceed with the attack attempt, which aims for the deepest and most extensive compromise possible.
Subsequently, with the aid of tools and manual testing, each parameter is tested with predefined values, and generic attack techniques for the platform in use are attempted.
Given the level of access obtained, we will attempt to perform unauthorized actions, extract data from the backend database, retrieve files or source code from disk, modify information, and, where possible, obtain full control of the machine and neighboring systems.
The Report is a simple and detailed document that summarizes the activity results and is divided into three different areas:
Executive Summary
Located at the beginning of the Report and no longer than one page, it is the high-level summary intended for Management.
Vulnerability Details
The technical part that describes in detail the vulnerabilities found and their impact, dedicated to the Security Manager.
Remediation Plan
A technical section with precise instructions on how to resolve the identified issues, dedicated to developers.
Working with us is pretty simple, just call the number or send an e-mail so that we can get to know each other and discuss about your IT Security needs.
Request a quotation for