
Petar Antonic
Belgrade, Serbia
Penetration Testing of Web Application (and supporting infrastructure)
(0) Remote 6 months ago
50 $ - Per hour
Aligned with PTES and OWASP Top 10
The web application penetration testing service evaluates the security of web-based applications and their supporting APIs in alignment with the Penetration Testing Execution Standard (PTES) and the OWASP Top 10.
The assessment focuses on identifying vulnerabilities that could be exploited by a real-world attacker, including weaknesses in authentication, authorization, session handling, input validation, and application logic. Testing activities are structured around OWASP Top 10 risk categories such as broken access control, injection flaws, cryptographic failures, security misconfiguration, and insecure design.
Both manual and automated techniques are used to validate exploitability and business impact. The test includes evaluation of application endpoints, exposed APIs, and integration points that directly support web application functionality. Supporting infrastructure components—such as web servers, application servers, and API gateways—are assessed insofar as they influence the security of the application.
The objective of the engagement is to identify vulnerabilities that could result in unauthorized access, data exposure, or manipulation of application functionality, and to provide actionable remediation guidance aligned with OWASP best practices.
The web application penetration testing service evaluates the security of web-based applications and their supporting APIs in alignment with the Penetration Testing Execution Standard (PTES) and the OWASP Top 10.
The assessment focuses on identifying vulnerabilities that could be exploited by a real-world attacker, including weaknesses in authentication, authorization, session handling, input validation, and application logic. Testing activities are structured around OWASP Top 10 risk categories such as broken access control, injection flaws, cryptographic failures, security misconfiguration, and insecure design.
Both manual and automated techniques are used to validate exploitability and business impact. The test includes evaluation of application endpoints, exposed APIs, and integration points that directly support web application functionality. Supporting infrastructure components—such as web servers, application servers, and API gateways—are assessed insofar as they influence the security of the application.
The objective of the engagement is to identify vulnerabilities that could result in unauthorized access, data exposure, or manipulation of application functionality, and to provide actionable remediation guidance aligned with OWASP best practices.
Pictures
Please sign in as a customer to give your feedback





