Web Penetration Test
What is a web application penetration test?
Web applications are the most targeted assets by attackers. Therefore, organizations should be the most sensitive in terms of information security and pay attention to the security of their web applications. In the Web penetration tests, all input fields of the application are determined by Ebruu researchers. After identifying the input fields in the applications, all the technical, business logic, and network-level vulnerabilities in the applications are detected and also exploited (if suitable) to create a POC. The tests are carried out using three different methods: manual, automated, and hybrid.
Web application testing methodology and stages:
1. Information Gathering
All publicly accessible passive and active information about the web application is collected and used as attack vectors during penetration testing. Ebruu researchers will also attempt to gather sensitive information, which is not exposed to any external or unauthorized entity.
2. Vulnerability Identification
For each of the web applications, a manual test is performed. Various vulnerability scanners are used to find vulnerabilities in the web application. Scan reports are then analyzed to confirm vulnerabilities and eliminate false positives. OWASP testing methodologies and business logic tests are specifically used in web application testing with separate tests for external and internal network threats.
3. Exploit Progress
Once vulnerabilities are identified, we look for available exploits for those vulnerabilities and identify what, if any, sensitive information can be gathered from them. These exploits can include maintaining access for later use or modifying configurations on the web application. These activities are all undertaken based on client agreement.
4. Report Writing
Ebruu researchers report all findings of the web application penetration test with risk ratings along with recommendations on solving the issues found in the web application.
5. Verification Test
We also provide a free verification test service for our clients, performed once for every single vulnerability after the client has fixed all security vulnerabilities.
Some of our web application penetration testing steps:
- Information Gathering via Whois Query
- Find all websites hosted on the same IP address.
- Find all websites via reverse DNS queries.
- Find all subdomains of the target domains.
- Perform a full TCP/UDP port scan for all website’s IP addresses.
- Identify new web interfaces on different TCP ports.
- Look at Google to find subdomains (Google dorks).
- Gather information (subdomains, leaked credentials) via Pastebin/GitHub.
- Discover new subdomains via DNS Dumpster.
- Perform brute force to the DNS server with a good wordlist to identify new subdomains.
- Analyze error messages, banner information, etc., for information gathering.
- Review Archive.org records for information.
- Perform subdirectory tests and identify Directory Listing vulnerabilities by visiting subdirectories.
- Use Google Dorks for Directory Listing.
- Gather information via robots.txt, elmah.axd, trace.axde.
- Conduct session stealing tests with Elmah.axd and Trace.axd.
- Identify target operating systems, databases, etc.
- Discover new files under newly discovered subdirectories with different extensions.
- Identify the CMS application in use on the target system.
- Scan the CMS application with specialized tools.
- Identify installed plugins of the CMS and known vulnerabilities in those plugins.
- Search for all known vulnerabilities related to the CMS version.
- Identify admin pages of the target websites.
- Check for any backdoors on the target systems with known web backdoors.
- Conduct data transmission security checks (HTTP usage, without HSTS header, unsecure SSL/TLS, etc.).
- Discover dangerous HTTP methods such as PUT and DELETE.
- Conduct username enumeration tests via error or warning messages.
- Perform brute force testing for web form fields.
- Attempt to bypass WAF systems.
- Manual crawling of the target applications.
- Identify all input fields throughout the target applications.
- Test hidden form fields.
- Perform source code reviews of HTML and JavaScript files.
- Identify and abuse unused CAPTCHA forms.
- Check for CSRF vulnerabilities on sensitive functions of the targets.
- Bypass anti-CSRF tokens.
- Conduct session manipulation tests.
- Test cookie attributes.
- Evaluate session ID weaknesses.
- Identify vulnerabilities in login functions and bypass techniques.
- Test for known and published vulnerabilities in the targets.
- Conduct two-factor authentication bypass tests.
- Evaluate session fixation vulnerabilities.
- Test for directory traversal vulnerabilities.
- Analyze authorization issues.
- Attempt to access other user assets unauthorized (files, private assets).
- Perform IDOR tests.
- Analyze weaknesses on the logout function of targets.
- Test privilege escalation with different role users.
- Focus on business logic issues within the target’s functions.
- Conduct HTTP Header tests and user agent manipulation tests.
- Perform X-Forwarded-For Restriction bypass tests.
- Execute XSS tests (reflected, stored, DOM, blind).
- Conduct SQL Injection tests, code injection tests, command execution tests, SSRF tests (local, remote), LFI/RFI tests.
- Focus on web service tests (ASMX, RESTful, WCF) and conduct business and technical tests on these services.
- Use effective attack vectors based on the used database/development platforms.
- Test for password reset functionality abuses.
- Perform account takeover via specific functionalities of the targets (password change, reset, etc.).
- Execute application level DoS tests (abusing functions, BoF, etc.).
- Test session timeout times, secure, HTTPOnly, and HSTS header uses.
- Conduct advanced authentication and authorization tests.
- Execute open redirection tests, file upload tests (command execution, stored XSS, DoS).
- Conduct LDAP injection, XML injection, and XML External Entity (XXE) tests.
- Perform buffer overflow and login bypass tests via long payload usage.
- Conduct DoS via code injection tests.
- Check for default or predictable password usage vulnerabilities.
- Post-exploitation via accessed systems (Tomcat, WordPress, etc.).
- Execute clickjacking vulnerability tests on significant functions of the targets.
- Fully automate scans of all websites.
If you would like to find out how Web Penetration Testing Service can be beneficial for your company or more information about our service, please contact our security experts to get a free quick consultation.