Web Application Penetration Testing
Deep, human-led security testing of your web applications - uncovering complex authorization flaws, business logic bypasses, and injection vulnerabilities that scanners miss.
What This Engagement Covers
The Service
Automated web vulnerability scanners only scratch the surface, producing false positives while failing to understand application business logic. Our web application penetration tests are conducted manually by senior security engineers. We evaluate your applications in both unauthenticated and authenticated states across multiple user roles, uncovering broken access control (IDOR/BOLA), authentication bypasses, session flaws, and data leakage vectors that represent real risk to your business.
What We Test
We test the complete application stack: modern single-page applications (React, Angular, Vue), legacy web applications, microservices, session management and JWT implementations, authentication and password recovery workflows, multi-factor authentication (MFA), role-based access controls (RBAC), file upload mechanisms, business logic workflows, third-party integrations, and API interactions.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
Our methodology aligns with the OWASP Web Security Testing Guide (WSTG) and OWASP Top 10. We begin by thoroughly mapping the application surface and role permissions. We then manually probe for authorization bypasses between users, analyze client-server trust boundaries, test input validation across all parameters, and chain vulnerabilities to demonstrate tangible business impact.
Application Mapping & Information Gathering
Crawling the application, mapping functional workflows, identifying hidden parameters, and documenting all roles.
Authentication & Session Architecture Review
Testing login flows, password resets, MFA bypasses, JWT signature flaws, and session termination behavior.
Authorization & Access Control Testing
Testing every endpoint across different roles to detect horizontal (IDOR) and vertical privilege escalation.
Input Validation & Injection Analysis
Testing for SQL injection, command execution, template injection, and cross-site scripting across all inputs.
Business Logic Flaw Identification
Testing race conditions, workflow state bypasses, price tampering, and transaction manipulation.
Server-Side Vulnerability Probing
Probing for SSRF, file inclusion, insecure deserialization, and dangerous XML processing (XXE).
Client-Side & Browser Security Evaluation
Analyzing CORS configurations, CSP policies, DOM-based flaws, and third-party script vulnerabilities.
Reporting & Developer Walkthrough
Authoring detailed reports with HTTP request/response proofs, CVSS scores, and hosting developer Q&A.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- Comprehensive technical findings report with CVSS v3.1 scoring
- Step-by-step reproduction proofs with raw HTTP requests and responses
- Remediation recommendations written specifically for software engineers
- OWASP Top 10 and ASVS compliance mapping scorecard
- Executive summary of application risk posture for business stakeholders
- Free retesting of all critical and high findings within 48 hours
- Formal Letter of Attestation for customer security reviews and audits
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to OWASP Top 10, OWASP ASVS, SOC 2 Type II, PCI-DSS v4.0, ISO 27001, PIPEDA, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Canadian web applications collecting personal data are subject to strict privacy controls under PIPEDA, Quebec Law 25, and provincial statutes. A rigorous web application penetration test demonstrates proactive compliance with legal duties of care and satisfies SOC 2 CC6.8 and PCI-DSS requirements.
Common Questions
Yes. In fact, authenticated testing accounts for the majority of severe vulnerabilities, particularly broken access control and business logic flaws. We request accounts for each user tier (e.g. Standard User, Manager, Administrator).
We can test either. Testing against a staging environment allows us to be more aggressive without customer impact, provided staging mirrors production configuration. Many clients have us test staging first and perform spot-checks on production.
We conduct black-box (no source code), grey-box (architecture docs and API specs), and white-box (source code access) testing. Grey-box testing offers the highest value for time, giving testers context while simulating realistic threat actor visibility.
We operate with strict rules of engagement, utilizing test accounts and clearly identifiable test data. We avoid destructive operations and coordinate closely with your engineering leads.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.