Web Application Security Testing
Authenticated and unauthenticated testing of web applications, APIs, roles, workflows and data access using the OWASP framework.
Know when to bring this work into the program.
Use web application testing before launch, after major change, or periodically when an application processes sensitive data or important transactions.
A scope built around the risk.
Authenticated and unauthenticated testing of web applications, APIs, roles, workflows and data access using the OWASP framework.
- Authentication, session management and account recovery
- Authorization across standard and administrative roles
- Input handling, APIs and business logic
- Sensitive data exposure, configuration and workflow abuse
Useful output for the people who must act.
- Authenticated and unauthenticated test results
- Reproducible evidence for development teams
- Business-impact explanation and remediation guidance
- Validation testing after fixes
A process designed for web application security testing.
Map roles and workflows
Begin with authentication, session management and account recovery and confirm the systems, people and evidence needed to answer the client’s specific questions.
Test application controls
Review authorization across standard and administrative roles. Then evaluate input handling, APIs and business logic to determine whether the relevant controls operate as intended.
Validate abuse paths
Assess sensitive data exposure, configuration and workflow abuse and connect the result to credible security, operational and business impact.
Support fixes and retest
Provide authenticated and unauthenticated test results and reproducible evidence for development teams, then align responsible parties around the next actions.
Move from activity to clarity.
Can one user access another user’s data or functions?
To answer this, Elteni analyzes authentication, session management and account recovery together with authorization across standard and administrative roles. The client receives authenticated and unauthenticated test results, with the evidence, context and next steps needed to act.
Can application workflows be manipulated?
To answer this, Elteni analyzes authorization across standard and administrative roles together with input handling, APIs and business logic. The client receives reproducible evidence for development teams, with the evidence, context and next steps needed to act.
Do APIs enforce the same controls as the interface?
To answer this, Elteni analyzes input handling, APIs and business logic together with sensitive data exposure, configuration and workflow abuse. The client receives business-impact explanation and remediation guidance, with the evidence, context and next steps needed to act.
The result does not have to live in another report.
Relevant findings, evidence, owners and remediation status can be centralized in the Elteni Platform as part of an ongoing relationship.
Explore the Elteni Platform →