Assessment

Web penetration testing

Secure your online presence and your business applications.

§ 01 · Overview

What is a web pentest?

A web penetration test (or web pentest) evaluates the security of a website by simulating realistic attacks. Whether it is a showcase site, an online store or a business tool, these applications play an essential role in your activity.

When they contain vulnerabilities, they can expose your data and the data of your users to major risks.

Objectives

Our audits highlight realistic risk scenarios, including:

  • Theft of sensitive data

  • Identity theft

  • Business disruption

  • Ransom demands

§ 02 · Approach

The HELX approach

To protect you from attacks, we audit the security of your website through penetration testing, so we can detect vulnerabilities before they get exploited. Our methodology builds on recognized security standards, which lets us assess any type of web application: CMS-based (Joomla, Drupal, WordPress and others) or built on a framework (Symfony, Laravel, Django, Node.js and more).

We help you secure your web applications and provide detailed, concrete recommendations. You protect your sensitive data, reassure your customers and keep running your business with confidence.

§ 03 · Formats

Audit types

A web pentest can start from different initial conditions. During our first conversation, we decide together which scenario best fits your needs.

Black box

Simulates a realistic attack by an external hacker with no prior access to the application.

Gray box

Simulates an attack by a malicious user or an attacker who has gained illegitimate access to the application.

White box

We use the source code for a deeper, more exhaustive analysis of the vulnerabilities present in your application.

§ 04 · Methodology

Methodology

Our web penetration tests follow a proven methodology covering the full exposure of your application, from server configuration flaws to the validation of user-submitted data.

  1. 01

    Information gathering

    Identification of the technologies in use (frameworks, proxies, WAF, servers and more) and analysis of the features to understand the context of the application.

  2. 02

    Application mapping

    Exploration of the features and entry points (web interfaces, APIs and others) to spot vulnerable components. Inventory of sensitive features (payment, file upload, etc.).

  3. 03

    Vulnerability research

    Search for common flaws (SQLi, XSS, SSRF, SSTI, request smuggling, CSRF) using scanners and in-depth manual testing.

  4. 04

    Exploitation

    Execution of the attacks to validate their exploitability in real-world conditions. Analysis of their impact and severity.

  5. 05

    Post-exploitation

    The previous phase gives us access to new information, so we look for and exploit further vulnerabilities in this new context.

  6. 06

    Risk assessment

    Classification of the flaws by severity and estimation of the impact on the application and the business.

§ 05 · Vulnerabilities we look for

A bit of technical detail

Our web audit methodology is built on well-known, proven standards such as OWASP, NIST and MITRE ATT&CK. In particular, we look for the following vulnerabilities:

  • Cross-site scripting (XSS)
  • SQL injection
  • Template injection (SSTI / CSTI)
  • Command injection and RCE
  • Arbitrary file upload
  • Exploitation of vulnerable components
  • Authentication bypass
  • Business logic vulnerabilities
  • Session hijacking, CSRF
  • Privilege escalation

Our other penetration tests

FAQ

Frequently asked questions

How much does a web penetration test cost?

Between €4,250 and €11,050 excl. VAT per application, depending on its size and the chosen approach. Small businesses, SMBs and non-profits get a 15% discount; the online quote simulator prices your scope in two minutes.

Can the test disrupt our production site?

No. We use neither destructive attacks nor denial of service, and every sensitive test is validated with you before execution. The test can also run on a staging environment if you prefer.

Black box or gray box: which should we choose?

Black box reproduces the real conditions of an attacker without an account; gray box adds test accounts to also cover authenticated features. For most applications, gray box offers the best coverage for the budget; we advise you during scoping.

What do we receive at the end?

A dual-audience report: an executive summary for decision-makers and technical detail per vulnerability (proof of exploitation, severity, concrete recommendation), with an oral debrief included and an optional retest of the fixes.

How is this different from an automated scan?

A scanner lists signatures, with plenty of false positives. Our experts actually exploit the flaws, chain them and assess the business impact: logic vulnerabilities, authentication bypasses and attack chains no tool detects on its own.

Tell us about your project.

Let us talk through your needs and expectations and build the right service for you.