Skip to content

Utilities Studio / Cybersecurity

Web application penetration testing

Find out whether one customer can reach another customer's data.

Test authentication, access controls, and business logic in your web application. Get reproducible findings and remediation guidance for your engineering team.

You need a pentest that fits the product you ship.

An enterprise customer wants a report, a release is approaching, or your permission model has changed. As a founder or engineering lead, you need coverage of the workflows that matter to your product. We test the agreed user roles and customer boundaries, with reproduction steps your developers can follow.

The assessment

Web application penetration testing

Web application penetration testing investigates how an attacker could abuse an application and its server-side behavior. We test the roles, workflows, and interfaces in scope, including requests a normal user would never make through the interface. Findings explain the access required, the affected data or function, and how to reproduce the issue.

Inside the scope

Authentication and sessions

Login, password reset, session handling, and the transitions between authenticated and unauthenticated access.

Authorization and tenant isolation

Attempts to reach another user's records, another customer's data, or functions reserved for a different role.

Business logic

Misuse of the agreed account, approval, purchase, or administrative workflows.

Input handling and exposed interfaces

Injection risks, file handling, and server-side validation across the application interfaces in scope.

Testing references

The WSTG provides a reference for web application security testing. Bring any required coverage or evidence mapping to the scoping call so it can be specified in the test plan.

OWASP Web Security Testing Guide (WSTG)

What your team receives

  • An executive summary explaining the business impact and what the assessment covered
  • Technical findings that identify the affected component and give your engineers evidence and reproduction steps
  • Remediation guidance for the affected components and a findings review with your team
  • Retest results for the agreed findings, with rounds, time window, and pricing specified before booking

Working with your team

From scope to remediation.

01

Scope the work and agree delivery

Confirm the assets, permissions, and production limits. Name the contacts and record the dates, reporting format, support arrangements, and retest terms.

02

Test and share the evidence

Investigate the agreed attack paths and validate findings. Keep your team updated and escalate critical issues immediately through the agreed channel.

03

Review findings and verify fixes

Walk your engineers through the report and remediation priorities. Carry out the agreed retesting and document which fixes worked and what remains unresolved.

What are you paying for?

Pricing depends on application complexity, the number of user roles, sensitive workflows, and the depth of testing. Several domains can belong to one application; one domain can contain several distinct applications. We scope the work around behavior and access.

Planning around your deadline

We confirm the testing window after reviewing the application and access requirements. Allow time for account setup, assessment, report review, and any retesting included in the proposal.

Pentest delivery

Know what to expect before the test starts.

When will we see findings?

We share validated findings during the test through the agreed secure channel. Critical issues go to your nominated contact immediately. Progress updates cover completed work, blockers, and what comes next.

What will the report contain?

Your engineers get affected assets, reproduction steps, evidence, and remediation guidance. We explain severity using the demonstrated impact. An executive summary sets out the business risk and the limits of the assessment.

Who helps us work through the fixes?

A technical findings review lets your engineers discuss the evidence and recommended fixes with us. We name the technical contact and agree the support period and response arrangements before testing.

What does retesting cover?

Retesting checks fixes to the original findings and records the result. Before booking, we specify the findings covered, retest rounds, time window, and any charges. New features or changed environments need a scope review.

Can findings go into our issue tracker?

We agree the findings format and handover method with your team. If you use Jira, Linear, or GitHub, we scope the export or ticket handover, required access, and treatment of sensitive evidence before testing.

When can we start and get the report?

Your proposal sets the start date, testing window, and report delivery date after we review scope and access. Bring your audit or release deadline so remediation and retesting can be planned around it.

Delivery references: NIST SP 800-115 and CREST's penetration testing programme guide.

The practitioner behind the work

Led by Sheeraz Ali.

Sheeraz Ali is our Head of Cybersecurity. His work spans application, cloud, network, and AI assessments. His personal track record includes leading pentests at Cobalt and building the internal pentest programme at SolarWinds.

Read Sheeraz's security background

Sheeraz's personal track record

Pentest engagements at Cobalt
245
Vulnerabilities identified at Cobalt
1,592
CVEs discovered
28+
Machines and labs authored at Hack The Box
300+

His website lists OSCP, CRTP, CRTE, CREST CRT and CPSA, CBBH, and CKA.

At SolarWinds, he delivered 120+ internal pentests. As CTO at Pwned Labs, he built a platform serving 40,000+ practitioners. He co-developed Mobexler, selected for Black Hat Arsenal, and presented research at Nullcon and c0c0n.

Explore his career timeline

FAQ

Questions before you book.

Do you test behind the login?

Yes, when authenticated testing is in scope. Provide accounts for the relevant roles so we can compare what each account should be able to do with what the application actually permits.

Is an automated scan enough for a web application?

A scan can identify some classes of weakness. Testing account boundaries and business logic also requires understanding the intended behavior and attempting to bypass it. We agree the testing approach around the application and the risks that matter.

Can you test a multi-tenant SaaS application?

Yes. Identify the tenant model and provide test accounts for separate organizations and roles. The scope can examine cross-tenant access, shared resources, and administrative functions.

Does web application testing include the API?

We identify the API endpoints used by the application during scoping. Broader API coverage, partner integrations, or endpoints outside the application may require a separate API assessment.

We had a pentest last year. What should we test now?

Bring the previous report and a list of changes to your code, permissions, or infrastructure. We can use those to scope the next assessment. Check which earlier findings were fixed and which fixes were verified; the date on the old report does not answer those questions.

All cybersecurity services

What do you need to get moving?

Tell us what your team needs to resolve, which systems are involved, and any deadline. We will work through the scope and reporting needs with you.