Skip to content
Safestorm
Menu

Core service

Web Application Penetration Testing

Manual, risk-led testing of web applications, authentication journeys and business-critical workflows.

A web application penetration test examines how an attacker could abuse your application in practice—not simply whether a scanner recognises a known vulnerability. Safestorm combines structured coverage with manual investigation of identity, access control, session handling and business logic, then validates findings using controlled, proportionate techniques.

Founder-led technical delivery

Why Safestorm for this assessment

Felix approaches application testing with the same objective-led mindset used in adversary simulation: understand what the application protects, identify the controls an attacker would challenge and follow weaknesses to a meaningful outcome. His hands-on methodology combines OWASP-led coverage with payload variation, encoding and manual investigation of server-side behaviours. The emphasis remains on authorisation and business logic—not inflating a report with low-value scanner output.

  • More than six years’ offensive-security experience
  • OSCP and OSEP certified
  • Red teaming, adversary simulation and control validation
  • Published IPv6 research presented at BSides London

Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.

What the assessment covers

Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.

  • Application mapping, attack-surface analysis and trust-boundary review
  • Authentication, MFA, password reset, account recovery and session management
  • Horizontal and vertical authorisation, including IDOR-style access-control failures
  • Business-logic abuse, workflow bypasses, race conditions and privilege escalation
  • Injection flaws, including SQL, NoSQL, operating-system command and template injection
  • Cross-site scripting, CSRF, CORS, clickjacking and browser security controls
  • JWT handling, token integrity and security assumptions between application components
  • XXE, path traversal, local file inclusion and unsafe file-processing behaviour
  • File handling, server-side request forgery, deserialisation and unsafe integrations
  • Security configuration, error handling, cryptography and sensitive-data exposure

Common risks identified

Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.

  • Unauthorised access to another customer’s records or privileged functionality
  • Account takeover through weak authentication or recovery controls
  • Manipulation of prices, approvals, limits or other business-critical workflows
  • Server-side compromise or access to internal services through injection or SSRF
  • Exposure of personal, commercial or security-sensitive information

A controlled process

How the engagement works

  1. Step 1

    Scope application roles, workflows, environments and testing constraints

  2. Step 2

    Agree rules of engagement, test accounts and data-handling arrangements

  3. Step 3

    Map the application, technologies, entry points and trust boundaries

  4. Step 4

    Perform systematic manual and tool-assisted testing

  5. Step 5

    Validate exploitability and impact without unnecessary disruption

  6. Step 6

    Report, debrief and retest agreed remediated findings

Who this service is suitable for

  • Customer-facing, partner-facing and business-critical internal applications
  • New applications approaching production or a material release
  • Applications changed significantly since their previous assessment
  • Teams responding to customer assurance, procurement or governance requirements

Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.

Methodology and industry references

Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.

Referencing a framework does not represent certification against it or guarantee compliance with every control.

Frequently asked questions

Is this just an OWASP Top 10 assessment?

No. The OWASP Top 10 is a useful awareness baseline, but it is not a complete testing methodology. Testing also considers the application’s architecture, user roles, business rules, data sensitivity and realistic attack paths.

Can testing take place in production?

Often, provided the risks and constraints are understood. Safestorm agrees safe-testing boundaries, prohibited actions, test windows and escalation contacts before work begins. A representative staging environment may be preferable for higher-risk scenarios.

What access is normally required?

Testing usually benefits from accounts for each relevant user role, application documentation and a technical contact. Both unauthenticated and authenticated attack surfaces can then be assessed.

Define the right scope

Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.

Discuss your requirements