Cyber security

Application penetration testing — web, mobile and desktop

In-depth application testing uncovers critical security weaknesses that automated scanners frequently miss. We carry out penetration tests using the internationally established OWASP methodologies, examining the security of web, mobile and desktop applications, APIs and other business-critical solutions.

Application penetration testing — a screen full of code

Our approach

We begin a penetration test by analysing the application and its environment in order to understand its architecture, functionality and potential risks. Next comes automated scanning for known vulnerabilities and misconfigurations — but the central and most important part of the engagement is in-depth manual testing by our experienced specialists. We examine business logic, authorisation and authentication mechanisms, session management and other complex scenarios that automated tools generally cannot detect.

Every vulnerability we find is verified, its real impact on the security of the system is assessed, and we produce a report with evidence, a risk rating and clear remediation recommendations.

The advantages of this approach

  • confirmed vulnerabilities with a real impact on system security,
  • discovery of flaws in business logic, authorisation and authentication,
  • no false positives,
  • a technical report with evidence and concrete remediation recommendations.
Penetration testing of web, mobile and desktop applications

Web applications

Web applications are often the most exposed entry point into an organization's information systems. Through manual penetration testing we check how resilient they are to modern cyber attacks and uncover vulnerabilities that could compromise the confidentiality, integrity or availability of data.

Our testing follows the OWASP Web Security Testing Guide (WSTG) and covers all the key risk categories, including:

  • authentication and session management,
  • access control and authorisation between user roles,
  • input validation (SQL injection, XSS, SSRF, XXE and other vulnerabilities),
  • flaws in the application's business logic,
  • application and web server configuration,
  • exposure of sensitive data and the security of communications,
  • the use of cryptography and the management of secrets,
  • the security of files, content uploads and APIs.
Application security — web (OWASP WSTG), mobile (OWASP MASVS/MASTG) and desktop applications: manual testing, business logic, practical recommendations

Mobile applications

We test Android (APK) and iOS (IPA) applications against the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Using both static (SAST) and dynamic (DAST) analysis we examine the security of the app itself, its communication with back-end systems and its resistance to attacks on the mobile device.

We pay particular attention to:

  • secure storage of data and cryptographic keys on the device,
  • communication with back-end APIs (TLS, certificate pinning, protection of data in transit),
  • authentication, authorisation and session management,
  • the security of local databases, files and the Keychain/Keystore,
  • the use of permissions and operating system security features,
  • protection against reverse engineering, tampering and re-signing,
  • analysis of the source or compiled code, the configuration and the bundled libraries,
  • the discovery of vulnerabilities that could allow privilege escalation, data leakage or abuse of the application.

By combining static and dynamic analysis with manual penetration testing we uncover vulnerabilities that automated tools frequently miss, and we set out clear recommendations for fixing them.

Reviewing web, mobile and desktop applications — authentication, access control, input validation and data security

Desktop (client) applications

We test desktop applications for Windows, Linux and macOS using a combination of static and dynamic analysis and manual penetration testing. We examine the security of the application, its communication with back-end systems, the protection of locally stored data and its resistance to attempts at abuse or modification.

We pay particular attention to:

  • authentication, authorisation and session management,
  • access control and the verification of user roles,
  • input validation (injection, XSS in hybrid applications, deserialisation and similar),
  • flaws in business logic,
  • the security of communication with APIs and other back-end services,
  • protection of locally stored data, credentials and configuration files,
  • analysis of executables, libraries and application dependencies,
  • protection against reverse engineering, tampering and unauthorised access to functionality.
Important
  • Our goal in a project is not merely to run a security assessment, simulate an attack and hand over a report, but to improve the security and resilience of your ICT environment.
  • On any project we can, if you wish, work together with your SOC team, measure how effectively your security controls detect activity, and prepare recommendations for improving the detection of attack techniques.
  • All security assessments and penetration tests are agreed in advance in terms of both schedule and methodology, and are carried out in a controlled, previously agreed manner.
Interested in this service?

We would be glad to discuss your needs

Contact us