Web application
Authenticated and unauthenticated assessment of a web application, aligned to OWASP ASVS, covering every layer from client-side logic to server configuration and business logic.
- Injection flaws, including SQLi, XSS, XXE, SSTI and CRLF
- Authentication, session management and single sign-on
- Access control, IDOR and privilege escalation between roles
- SSRF and out-of-band exploitation
- Business logic and workflow abuse
- Third-party component and supply chain risk