The Web Application Penetration Testing simulates a malicious application user that attacks the application in scope – assuming knowledge of credentials by attempting to circumvent the application’s logic or by taking advantage of potential application’s security weaknesses in order to obtain unauthorized access to the data served by the application with respect to the confidentiality, integrity and availability of the latter.
More specifically, the attack vectors within the context of the testing will evaluate the ability of a malicious user to:
- Obtain unauthorized access to sensitive data
- Modify, corrupt or destroy data
- Attack application’s users
- Perturb the application and its components
- Change or introduce software, malicious or otherwise