Skip to content
Zyberum Cyber Security Firm
Menu

Web application & API pentest

Your web app has a login. We check what is behind it.

Scanners find missing headers. We find the request that returns another customer’s data. Manual testing of web applications and APIs, with proof for every finding and a fix your developers can apply.

  • OWASP Top 10 & API Top 10
  • Business logic and access control
  • Retest included

In short

A web application penetration test is a manual security assessment of a web application and its APIs. Testers look for flaws in authentication, session handling, access control (IDOR, BOLA, BFLA), input handling and business logic, following the OWASP Top 10 and the OWASP API Security Top 10. Zyberum delivers CVSS-rated findings with proof-of-concept, fixes and a retest at a fixed price.

What we test

Where web applications really break

Authentication & sessions

Login, password reset, multi-factor, single sign-on, tokens and session handling.

Access control

Can user A read or change the data of user B? IDOR, BOLA and BFLA are the findings with the biggest impact.

Business logic

Steps skipped, prices changed, limits bypassed: the flaws no scanner understands.

Injection & input handling

SQL and command injection, cross-site scripting, server-side request forgery, unsafe deserialisation.

APIs

REST and GraphQL: excessive data exposure, mass assignment, missing rate limits, undocumented endpoints.

Configuration

Exposed admin interfaces, verbose errors, outdated components and weak transport security.

Why manual

The serious findings are logic, not syntax

In the IoT products we tested recently, the worst findings were not exotic exploits. They were API calls that simply returned or changed other customers’ devices, because the server trusted an ID in the request.

That kind of flaw only shows up when someone understands what the application is supposed to do, and then tries what it should not allow. That is what we spend our time on. Our self-hosted AI models help us cover more endpoints in the same time, and every finding is verified by a tester.

Case studies

API flaws with real impact

FAQ

Web pentest FAQ

Do you test on production or staging?

A staging system with production-like data is best, because we can test without risk to your users. Testing on production is possible with agreed limits.

What do you need from us?

The URL, test accounts for each role, and API documentation if it exists. For a white box test, access to the source code.

How long does a web application pentest take?

Typically 5 to 10 days of testing for one application, depending on the number of roles and features.

Get started

Get your web or API pentest scoped in 15 minutes

Tell us about the application, its roles and its APIs. You get a fixed-price offer after the call.

  • Scope by roles, features and API endpoints
  • Fixed-price offer after the call
  • Test accounts and a staging system are all we need
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet your web pentest quote

Pick a time that suits you

Open in a new tab