Web application penetration testing
Authenticated and unauthenticated testing of application behaviour, focused on the trust boundaries an attacker can actually cross.
- Authentication
- Authorization and access control
- Session management
- Business logic
- Input validation
