Web Assessment

Service Overview

Dognet Technologies Web Assessment is a security testing activity specialized in web applications—Business portals, e-commerce platforms, SaaS applications, web-based management systems, REST APIs and GraphQL—conducted by certified specialists with an approach faithfully replicating the techniques used by real attackers. This is not a simple automated vulnerability scan: it is a thorough manual analysis that identifies logical business vulnerabilities, multi-step attack chains and architectural weaknesses invisible to scanners.

Web Assessment

WebPenTest

The web application is today the main attack surface for the vast majority of organizations. According to the Verizon Data Breach Investigations Report, web applications are the primary attack vector in 43% of violations. A systematic Web Assessment allows you to identify and correct these exposures before they are exploited by malicious actors.

Methodology and Framework

Testing follows the OWASP Testing Guide (OTG) in its most up-to-date version, systematically covering all vulnerability categories defined by the OWASP Top 10 and OWASP Application Security Verification Standard (ASVS). We integrate techniques from the PTES (Penetration Testing Execution Standard) and mappiam the findings towards the MITRE ATT&CK for Enterprise framework to contextualize any vulnerability in real threat actor TTPs.

Testing areas

Testing covers the entire application surface through the following areas:

  • Authentication and authorization: bypass of login mechanisms, brute force protection, account enumeration, reset password insecure, vertical and horizontal authorization, IDOR, JWT manipulation, OAuth misconfiguration.
  • Injection: SQL Injection (error-based, blind, time-based, out-of-band), NoSQL Injection, LDAP Injection, XML Injection, template (SSTI), OS Command Injection, HTTP Header Injection.
  • Cross-Site Scripting (XSS): reflected, stored and DOM-based XSS, bypass filters and WAF, escalation towards takeover accounts and session hijacking.
  • Cross-Site Request Forgery (CSRF) and Clickjacking: CSRF protection verification on state-changing operations, Content Security Policy analysis and X-Frame-Options header.
  • Insecure Direct Object Reference (IDOR) and Mass Assignment: unauthorized access to other users' resources, parameter manipulation, mass assignment in REST APIs.
  • Security Misconfiguration: missing or wrong HTTP security header, CORS misconfiguration, listing directory, exposed file backups, verbose error handling, obsolete and vulnerable components.
  • Business Logic Flaws: price and quantity manipulation, bypass of mandatory step in workflows, race conditions, elusion of antifraud controls, abuse of coupons and promotions.
  • API Security: OWASP API Top 10—Broken Object Level Authorization, Broken Authentication, Excessive Data Exposure, Lack of Resources Limiting, Function Level Authorization, Mass Assignment, Security Misconfiguration.
  • Session management: session fixation, session prediction, insufficient session expiry, secure and httponly cookie flags, token entropy analysis.

Testing mode

We offer three operating modes that can be adapted to customer needs: Black Box (no prior information, simulates an external attacker), Grey Box (access with standard user credentials, simulates an attacker with limited access or unprivileged insider), White Box (full access to documentation, source code and administrative credentials, maximise coverage and depth of analysis). For most business-critical applications we recommend the Grey Box or White Box approach, which guarantees superior coverage in the same time window.

Deliverable

The report includes executive summary with overall risk rating; detailed findings with technical description, CVSS 3.1 severity, exploitability tests (screenshot, payload, request/response HTTP) and specific remediation; prioritization matrix for remediation; and free networksting on critical and high findings after correction by the development team.

EnglishenEnglishEnglish