Web Application Security Testing


Request Information

Netcraft's Web Application Testing is an Internet security audit, performed by experienced security professionals. A key feature of the service, and one which cannot be covered by relying solely on automated testing, is application testing.

The service is designed to rigorously push the defences of Internet networks and applications. It is suitable for commissioning, third party assurance, post-attack analysis, audit and regulatory purposes where independence and quality of service are important requirements.

A final written report provides an analysis of any security or service problems discovered together with proposed solutions, links to detailed advisories and recommendations for improving the security of the service under test.

Web Application Testing covers:

Customers who have had tests performed by Netcraft include Aegon, Amp, American Express, Capita, Energis, Lloyds of London, Northern Rock, and Securicor.

Typical issues discovered in an application test include
Back doors and debug optionsCross-site scripting
Broken ACLs/Weak passwordsWeak session management
Buffer overflowsForceful browsing
CGI-BIN manipulationForm/hidden field manipulation
Command injectionInsecure use of cryptography
Cookie poisoningRisk reduction to zero day exploits
SQL injectionServer misconfigurations
Well-known platform vulnerabilitiesErrors triggering sensitive information leak

The duration of a test depends on the size and complexity of a site, but can start from 6 days (approx four days testing, two writing up), at a cost of $1700 US per day ( £900 +VAT).

Please contact us by email, or phone +44-1225-447500 , to discuss your particular requirements.

See also: