Standard Penetration Test of the Web Application
Description
The goal of the standard penetration test is to reveal as many as possible of the most critical security vulnerabilities in the web application / web server during 3 days, exploit them and gain a privileged access if it is possible.
The test consists of:
* Information Gathering – information about the target system is identified and documented, including web server version, its modules, used programming framework, WAF, identification of all entry points
* Enumeration and Vulnerability Mapping – using intrusive methods and techniques (specially constructed HTTP requests) to identify potential vulnerabilities (manual inspection or special vulnerability scanners and fault-injection proxies are used)
* Exploitation – attempting to gain access through vulnerabilities identified in the previous phase. The goal is to gain user and privileged (administrator) access to the application or operating systems (custom exploit scripts or exploit frameworks are used)
Features:
* reveals the most serious vulnerabilities (SQL/LDAP injections, XSS/CSRF, buffer overflows, business logical flaws, authentication bypass, local file inclusions)
* due to the fact that a manual inspection is used, the test is highly recommended when your automatized security scanners have already failed
* technical report with executive summary, all revealed vulnerabilities, risk levels and recommendations
For more information https://nethemba.com/services/application-security/standard-penetration-test/86R7nc7BCdz8nzvBQeyFyebPEEi1gq7D6BLr3zmnZvrJBMfACysM4MR38uvAY2CXondVhpoYRAUvtHhSc3dXHbESPADZP5c
Tags: penetration test, security audit
About the trader
N/A
N/A
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEAAAAABYJKwYBBAHaRw8BAQdAC3H8ushAd8rN/D49u2ldCHbCassazndGmlo3 eErr0U20Fm5ldGhlbWJhQHhtcmJhemFhci5jb22IlAQTFgoAPBYhBEu++QMH8edZ Hf0IIykrWXDb9Y7TBQIAAAAAAhsDBQsJCAcCAyICAQYVCgkICwIEFgIDAQIeBwIX gAAKCRApK1lw2/WO00vGAQC/tULbGun29akkQ0QZMty8FK5Dh78jUS7xpGaj/OV8 2wEAlz62yI5Xkja3dogplYa51Kf8Y+/Vmd7/xNwyapqBQwy4OAQAAAAAEgorBgEE AZdVAQUBAQdArgUWsgt+8iBzLBCq7elELG/E78hz1aQ675W8baQxXhsDAQgHiHgE GBYKACAWIQRLvvkDB/HnWR39CCMpK1lw2/WO0wUCAAAAAAIbDAAKCRApK1lw2/WO 08LdAP9DklW4ekAMwZohVWhuIGkllFlsD37VH+q57y/4FgCdhQEA7o6RvCpqlMg3 EJLIcm0STs+GYB2bHKtm9FYgKg2QtQo= =6QTI -----END PGP PUBLIC KEY BLOCK-----