Basic offer for penetration test
focusing on OWASP Top 10
Basic offer for penetration test
focusing on OWASP Top 10
You have a web application with a protected area and features such as profile management, file storage and a contact form. We test your application for the top 10 risks according to OWASP and more.
Scope
- Purely technical testing of your web application
- Purely external examination from different roles: anonymous visitor, standard user, privileged user
- Suitable for most modern web applications
Your benefits: what is investigated?
- Manual testing of the web application for the top 10 security risks according to OWASP
- Manual testing of compliance with the recommendations for secure web applications
- Oriented towards practical issues
• faced by standard users: is control over my data guaranteed? Is access by third parties adequately secured?
• faced by administrators: are the administrative features secured against unauthorized access?
Can the application be misused to the detriment of third parties? - Includes a vulnerability scan of the web server to test for vulnerabilities in the software components used or in the configuration
Result (output)
- Report with executive summary
- The report contains results and analyses, evidence and recommended measures
- Presentation and discussion of the report online or on site
Differentiation from basic offer of penetration test focusing on intrusion
- Thorough testing of the features and roles of the web application for vulnerabilities
Customer profile: who is the basic offer of the penetration test focusing on the OWASP Top 10 aimed at?
- Companies that offer services via their own web portal
- SMEs and startups
Resource planning: little effort required from you
The effort for you amounts to around 12 hours. This time is divided up as follows:
- Participation in the kick-off meeting and report meeting
- Description of functional scope, intended use, special cases and worst-case scenarios, to ensure rapid training of the tester
- Setup of the accounts required for the testing; deletion of the accounts upon project completion
- Possible activation of our IP range for the tests
Direct line to our audit team