Web Application Penetration Testing

Web applications are one of the most common types of software in use today. Due to their complexity and ubiquity, web applications represent unique security challenges to an organisation. Modern web applications handle increasingly sensitive data, so it is important to ensure that they do not introduce significant risk to you.

Web applications include websites and programs that “utilizes web browsers and web technology to perform tasks over the Internet

What is a web application penetration test?

A web application penetration test aims to:

  • Uncover vulnerabilities and insecure functionality
  • Identify the OWASP top 10 most critical security risks
  • Identify additional security issues resulting from insecure development practices in the design, coding and publishing of software or a website

This generally includes:

  • Testing user authentication to verify that accounts cannot compromise data
  • Assessing the web applications for flaws and vulnerabilities, such as broken authentication and security misconfiguration
  • Confirming the secure configuration of web browsers and identifying features that can cause vulnerabilities
  • Safeguarding web server security and database server security.

The vulnerabilities are presented in a report that allows you to assess the relative business risk that they represent along with the required remedial action. These can then be resolved in line with your budget and risk appetite.

Julie Jordan-Spence – FSB

Trevor is concise, professional and extremely knowledgeable in all of his subjects. He recently gave a very interesting and thought provoking talk to the Federation of Small Business Virtual Networking group that I host here in Leicester, on the subject of Cyber crime. It stimulated many questions and much discussion, all of which made for a very positive meeting.

Julie Jordan-Spence