Web Application Penetration Test

Price: $5,500.00

Deep manual testing of a web application and its API against the OWASP Top 10 and business-logic abuse.

Share

Automated scanners find the noisy issues. We focus on the ones they miss: broken authorisation between tenants, abusable workflows, and authentication logic that can be bypassed rather than brute-forced.

What the engagement covers

  • Authentication, session management and password reset flows
  • Authorisation, multi-tenant isolation and IDOR testing
  • Injection, SSRF, deserialisation and file-handling flaws
  • Business-logic and workflow abuse
  • API endpoint testing, including undocumented routes

What you receive

  • Findings with request/response evidence and reproduction steps
  • Developer-oriented remediation guidance per finding
  • Executive summary for stakeholders and customers
  • Live debrief with the development team
  • Free retest of all findings within 30 days

Typical duration: 6 to 10 business days
Pricing: the listed figure is a starting point; final price follows a scoping call and depends on the size of the environment.
Authorisation: testing begins only once a scope and authorisation letter is signed by an accountable owner of the systems in scope.

Request a scoping call

  • Reference
    BBS-PT-WEB
Authorised testing only
Every engagement runs under a signed scope and authorisation letter.
Confidential by default
Mutual NDA before scoping. Your findings are never shared or resold.
Free retest included
We re-verify every finding within 30 days of remediation at no cost.

Comments (0)

No customer reviews for the moment.

1 other product in the same category

Loading...
Back to top