Web Application Penetration Test
Price:
$5,500.00
Deep manual testing of a web application and its API against the OWASP Top 10 and business-logic abuse.
Automated scanners find the noisy issues. We focus on the ones they miss: broken authorisation between tenants, abusable workflows, and authentication logic that can be bypassed rather than brute-forced.
What the engagement covers
- Authentication, session management and password reset flows
- Authorisation, multi-tenant isolation and IDOR testing
- Injection, SSRF, deserialisation and file-handling flaws
- Business-logic and workflow abuse
- API endpoint testing, including undocumented routes
What you receive
- Findings with request/response evidence and reproduction steps
- Developer-oriented remediation guidance per finding
- Executive summary for stakeholders and customers
- Live debrief with the development team
- Free retest of all findings within 30 days
Typical duration: 6 to 10 business days
Pricing: the listed figure is a starting point; final price follows a scoping call and depends on the size of the environment.
Authorisation: testing begins only once a scope and authorisation letter is signed by an accountable owner of the systems in scope.
-
ReferenceBBS-PT-WEB
Every engagement runs under a signed scope and authorisation letter.
Mutual NDA before scoping. Your findings are never shared or resold.
We re-verify every finding within 30 days of remediation at no cost.
Comments (0)
Your review appreciation cannot be sent
Report comment
Report sent
Your report cannot be sent