Web Application Penetration Testing
Manual, researcher-led web application pentesting across your full attack surface
What this engagement covers
The service
Our web application penetration testing services combine proprietary automated surface discovery with rigorous manual exploitation by senior offensive security researchers. We uncover deep business logic flaws, broken object-level authorization (IDOR/BOLA), authentication bypasses, and chained multi-step exploits that automated DAST scanners miss—complete with zero false positives and complimentary retesting.
What we test
We thoroughly assess modern multi-tenant architectures, single-page applications (React, Vue, Next.js), GraphQL and REST APIs, and server-side runtimes. Testing covers authentication mechanics, session management, authorization boundaries, payment workflows, file execution paths, third-party integrations, and both OWASP Top 10 and OWASP ASVS standards.
Scoping & Assessment Depth
Gray Box Testing (Recommended)
Most PopularSimulates an authenticated user attempting to escalate privileges or breach tenant isolation. Testers receive accounts for each role tier to thoroughly test authorization (IDOR/BOLA), role separation, and business logic.
Black Box Testing
Adversary SimulationZero-knowledge testing simulating an unauthenticated external adversary targeting your public attack surface, perimeter endpoints, forgotten assets, and authentication portals.
White Box / Hybrid Testing
Maximum DepthTesters are provided with architecture blueprints, API schemas, and source code access alongside live testing. Delivers the deepest vulnerability discovery for high-risk applications and pre-launch architectures.
Attack Surface & Vulnerability Vectors
Authentication & Session Integrity
MFA bypasses, credential stuffing resilience, JWT signature manipulation, session fixation, token entropy, and password reset logic flaws.
Authorization & Multi-Tenancy (IDOR)
Insecure Direct Object References (IDOR), vertical/horizontal privilege escalation, and cross-organization data leakage in multi-tenant SaaS.
Business Logic & Workflow Abuse
Multi-step state manipulation, race conditions, coupon/discount stacking, payment gateway tamper, and business process circumvention.
API, REST & GraphQL Endpoints
Broken Object Level Authorization (BOLA), mass assignment, batching attacks, rate-limit evasion, and unauthenticated introspection queries.
Injection & Server-Side Execution
SQLi, NoSQLi, Server-Side Request Forgery (SSRF), Server-Side Template Injection (SSTI), Command Injection, and XML External Entities (XXE).
Client-Side & Frontend Security
DOM-based and stored Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), CORS misconfiguration, and CSP bypass techniques.
How we run it
Aligned with the OWASP Web Security Testing Guide (WSTG v4.2) and the Penetration Testing Execution Standard (PTES), our testing combines automated surface footprinting with hands-on manual abuse of application logic. Every vulnerability is validated with working proof-of-concept exploits, CVSS v3.1 scoring, and developer-level remediation steps. All findings stream directly to your Talon portal in real time.
Reconnaissance & Attack Surface Mapping
We map the full digital perimeter of your web application, discovering hidden parameters, subdomains, forgotten endpoints, legacy routes, API documentation, and third-party integrations using OSINT and active probing.
Automated Baseline Scanning & Discovery
We deploy proprietary scanners and industry-standard tools to establish an architectural baseline, identify known CVEs, outdated libraries, and misconfigurations while eliminating scanning noise through manual validation.
Authentication & Session Security Review
In-depth manual testing of login logic, password reset mechanisms, Multi-Factor Authentication (MFA) bypasses, JWT signature verification, session token randomness, timeout handling, and session fixation vulnerabilities.
Authorization & Access Control Testing (IDOR / BOLA)
Manual testing across multi-tenant boundaries and privilege tiers. We probe for Insecure Direct Object References (IDOR), horizontal privilege escalation (user-to-user), and vertical privilege escalation (user-to-admin).
Business Logic Flaws & Workflow Abuse
We deconstruct multi-step business workflows (e.g. checkout, payment gateway callbacks, coupon application, voting, onboarding) to find state manipulation flaws that automated vulnerability scanners are blind to.
Input Validation, Injection & Deserialization
Manual injection testing targeting SQL Injection, NoSQL Injection, Server-Side Template Injection (SSTI), Command Injection, Cross-Site Scripting (XSS), XML External Entities (XXE), and insecure object deserialization.
API, Microservices & GraphQL Assessment
We inspect REST and GraphQL endpoints consumed by your web client, testing for Broken Object Level Authorization (BOLA), mass assignment, batching attacks, rate-limit bypasses, and unauthenticated schema introspection.
Exploitation, Evidence Capture & Chained Impact
Every valid exposure is manually weaponized in a non-destructive manner to demonstrate real-world business impact. We capture reproduction curl commands, HTTP request/response logs, and video PoCs for your developers.
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Executive summary with business impact and risk posture analysis
- Technical vulnerability report with verified CVSS v3.1/v4 scores
- Working proof-of-concept (PoC) exploit scripts and curl reproductions
- Step-by-step developer remediation guidance with code examples
- Auditor-ready compliance crosswalk (PCI-DSS 4.0, SOC 2, HIPAA, ISO 27001)
- Talon real-time portal access with bi-directional Jira/GitHub ticket sync
- Post-remediation retest report validating fixes before attestation
- Formal, signed Letter of Attestation for customers and security questionnaires
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Auditor-Ready Compliance Crosswalk
| Framework | Control Section | Testing Evidence & Report Deliverable |
|---|---|---|
| PCI DSS v4.0 | Requirement 11.4.3 | Annual external and internal penetration testing of the cardholder data environment (CDE) and web-facing application layer by qualified personnel. |
| SOC 2 Type II | CC4.1, CC4.2, CC7.1 | Formal penetration testing evidence and remediation tracking formatted specifically for CPA auditor workpapers to validate continuous security controls. |
| HIPAA Security Rule | 45 CFR § 164.308(a)(1) | Technical evaluation and vulnerability assessment verifying that electronic Protected Health Information (ePHI) data stores and workflows cannot be compromised. |
| ISO/IEC 27001:2022 | Control A.8.8 | Technical vulnerability management through independent penetration testing, risk-prioritized findings, and verified corrective action plans. |
| FedRAMP / NIST | NIST SP 800-53 Rev 5 CA-8 | Adversary-driven penetration testing simulating realistic threat vectors, satisfying federal agency authorization and continuous monitoring mandates. |
Findings are mapped to OWASP Top 10, PCI-DSS, HIPAA, SOC 2, ISO 27001, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Frequently Asked Questions
Direct answers on scoping, methodology, compliance validation, and deliverables.
An automated vulnerability scanner only matches known CVE signatures and basic patterns, missing up to 70% of critical flaws such as business logic errors, authorization bypasses (IDOR), and complex chained exploits. Lorikeet Security's web app pentest is researcher-led: senior offensive testers manually interrogate your application logic, probe role boundaries, and prove real-world business impact with zero false positives.
Yes. Our reports are built specifically for compliance acceptance. They map directly to SOC 2 Type II Trust Services Criteria (CC4.1/CC4.2) and meet all requirements of PCI DSS v4.0 Requirement 11.4.3 for application-layer testing. Major CPA audit firms and Qualified Security Assessors (QSAs) accept our reports without pushback.
Yes. Every web application penetration test engagement from Lorikeet Security includes free retesting within 30 to 60 days of initial report delivery. Once your engineers deploy fixes, our testers re-run the exact attack chains to verify resolution and issue an updated, clean letter of attestation for your customers and auditors.
A standard web application assessment typically takes 1 to 2 weeks for active testing. However, unlike traditional firms that make you wait weeks for a PDF, Lorikeet publishes verified vulnerabilities to your real-time Talon portal as they are confirmed, allowing your developers to begin remediation immediately.
Our web app pentests start from $7,500. Exact pricing is scoped during a single call based on application size, number of dynamic user roles (e.g. Admin, Member, Read-Only), number of API endpoints, and single-tenant vs multi-tenant complexity. All quotes are strictly fixed-price—there are no surprise hourly overages or unexpected change orders.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.