APOLLOSEC

Web application and API penetration testing

Manual testing of your web applications and APIs by consultants who think like attackers. We find the authentication, access control and business logic flaws that automated scanners miss, and show your developers how to fix them.

Why scanners are not enough

Your web applications are the part of your organisation that anyone on the internet can talk to. They hold customer data, take payments and connect to the systems behind them, and they change with every release. A scanner can tell you about a missing header or an outdated library. It cannot tell you that one customer can read another custome’s invoices by changing a number in a request.

That class of flaw, broken access control, sits at the top of the OWASP Top 10 for a reason. Finding it takes someone who understands what the application is supposed to do, then tries to make it do something else.

What we test

  • Authentication

    Login, registration, password reset, MFA and single sign-on, plus how sessions, tokens and cookies are issued and expired.

  • Access control

    Whether one user can reach anothe’s data or an admin function: horizontal and vertical privilege escalation, insecure direct object references and tenant separation.

  • Business logic

    Workflows that can be skipped, repeated or reordered: discounts, approvals, limits, refunds and payments.

  • Injection and input handling

    SQL and NoSQL injection, cross-site scripting, template injection, server-side request forgery and file upload abuse.

  • APIs

    REST and GraphQL endpoints tested directly, including those the interface never calls, against the OWASP API Security Top 10.

  • Configuration and components

    TLS, security headers, CORS, exposed admin panels, debug features and known-vulnerable libraries.

How the engagement runs

  1. Scope

    We agree the applications, environments and user roles, and anything off limits. A staging copy with production-like data is often the safest place to test.

  2. Map

    We walk the application as each role, record every endpoint and parameter, and load your API definitions if you have them.

  3. Test

    Manual testing guided by the OWASP Web Security Testing Guide, supported by tooling. Serious findings go into the portal as soon as we confirm them.

  4. Report and retest

    The report follows within five working days, with reproduction steps and fixes your developers can use. We then retest to close each finding.

What you get

  • Each finding proved. Severity, the request and response that demonstrates it, the business impact and a specific fix.
  • A summary for non-specialists. What was tested, what was found and what to do first, in plain language.
  • Retest results. Evidence that each issue is closed, for your customers and auditors.

When to commission it

  • Before a new application or major feature goes live.
  • After changes to authentication, payments or permissions.
  • When a customer, insurer or auditor asks for evidence of testing.
  • At least yearly for applications holding personal or payment data, and more often for those that change every week.

Questions we get asked

What is the difference between API testing and web application testing?

A web application test covers what a user can reach through the browser. An API test goes straight to the endpoints, including ones the interface never calls. Most modern applications are an interface on top of an API, so we usually scope and test both together.

Do you test the logged-in parts of the application?

Yes. Most serious flaws sit behind the login. We ask for at least two accounts for each user role, so we can test whether one user can reach anothe’s data.

Can you test our live environment?

We can, with care. We agree rules for anything that writes data, sends email or takes payment. Where staging closely mirrors production we usually test there, then confirm key findings in production.

Which standards do you follow?

The OWASP Web Security Testing Guide for method, the OWASP Top 10 and API Security Top 10 for coverage, and CVSS for severity. If you need results mapped to OWASP ASVS levels, tell us when we scope.

Releasing something new? Have it tested first.

Talk to us