Information Infrastructure, Insight

@textonline chat OR CALL

01483 520 200

Web Application Testing

Web Application testing evaluates the security behavior of interactive web sites ranging from applications used as eCommerce and extranet services through to sites offering simple fill-in "Contact Us" forms.

MTI Web Application Testing: Overview

MTI have developed an extensive Web Application testing methodology that is based on the OWASP Top Ten but also goes above and beyond this to incorporate many bespoke testing methodologies that our consultants have designed over many years of carrying out these types of test.

As trusted experts, MTI examine what is predominantly accessed over HTTP or HTTPS and attempt attacks that the traditional network firewall isn't designed to protect against. Interactive extranet and eCommerce applications can take thousands of man hours to code and are often very complex. Whilst some automated tools can find some issues, no web application can be reliably and fully tested using automated tools only and they require testing by experienced consultants.

Depending on the application, we perform appropriate testing in the following areas:

  • Authentication
  • Authorisation
  • Account Management
  • Session Management
  • Cross Site Request Forgery (CSRF)
  • Encryption
  • Hidden field manipulation
  • SQL and Script injection attacks
  • Meta character stripping
  • Parameter tampering
  • Forceful browsing
  • Form posting vulnerabilities
  • Character bounds checks
  • Buffer overflow checks
  • Cross-site scripting
  • Source code disclosure
  • Back doors and debugging options
  • Past errors disclosed (incl. Google diving)
  • Newsgroup searches for information and technicians' query disclosures
  • Third-party mis-configurations and insecure default configuration settings
  • Known software vulnerabilities
  • Code Reviews

Next Steps...

If you would like more information regarding Web Application Testing, please contact the MTI penetration testing team to discuss your requirements.

@text Request Call Back
@text Request Pricing
  • CHECK Green Light Member

    CHECK Green Light Member

  • Member of the Council of Registered Ethical Security Testers

    Member of the Council of Registered Ethical Security Testers

Follow MTI on TwitterFind us on LinkedInView our You Tube channel

Join us, @451Research, #EMC, #Cisco & #VMware at the @TheNMMUK and discover a new way of delivering IT efficiency.

  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
Seminar: MTI VSPEX Event at The Aberdeen Maritime Museum
Wed May 29 2013 - 1:30 PM
Location: The Aberdeen Maritime Museum

Seminar: MTI VSPEX Event at The National Motorcycle Museum with 451 Group
Thu Jun 06 2013 - 9:30 AM
Location: The National Motorcycle Museum

See all Events & Shows