Skip to main content
HDWSec
HDW Sec penetration testing illustration

Web Pentest

Find your vulnerabilities before an attacker does.

Based in Paris, our team conducts penetration tests on your systems, applications and networks to reveal your vulnerabilities and deliver a clear, prioritised remediation plan.

France Cybersecurity Label France Cybersecurity Label
10+ Years of experience
500+ Tests completed
100+ Satisfied clients
Expertise forged in critical environments

The web attack surface

A web application is a living surface, not a fixed perimeter

Every endpoint, every parameter, every API call and every user role widens the surface an attacker can probe. Modern frameworks do not neutralise business logic: a missing access check, a tamperable identifier or a bypassable workflow stay invisible to automated tools. Our penetration test draws on the OWASP Top 10, ASVS and WSTG references without being limited to them: we reason as attackers to expose the chains of flaws that lead to a real compromise.

Four families of flaws, tested by hand

Injections and server-side execution

SQL and NoSQL injection, command injection, template injection (SSTI), SSRF and unsafe deserialisation. We look for the points where user input reaches an interpreter, a query or an internal network call without sufficient validation.

Access control and business logic

IDOR/BOLA, horizontal and vertical privilege escalation, workflow bypass. We verify that every object and every action is tied to the authorised user, rather than loaded by identifier with no ownership check.

Authentication and session management

Password weaknesses, JWT token handling, OAuth/OIDC and SSO flows, bypassable MFA. We probe sign-up, login, password reset and session lifetime to surface account takeover paths.

APIs, XSS and data exposure

REST and GraphQL APIs (exposed introspection, field over-exposure, missing rate or query-depth limits), stored, reflected and DOM-based XSS, leakage of sensitive data and secrets in responses, client code or error messages.

Pentest walkthrough

A rigorous methodology, concrete results.

1
Step 1: Before the pentest

Scoping & preparation

Validation of the scope (URLs, subdomains, environments), exclusions and constraints. Setting up Grey Box access and the test plan.

2
Step 2: Day 1

Mapping & reconnaissance

Building an exhaustive view of the attack surface: pages, endpoints, flows, roles and components. Identification of technologies, authentication mechanisms and open-source intelligence leaks.

3
Step 3: Days 2 to 5

Security testing

In-depth manual tests and targeted automation across the full OWASP spectrum: authentication, authorisations, injections, XSS/CSRF, business logic, configuration and, where applicable, AI attacks.

4
Step 4: Day 5

Consolidation & risk assessment

Validation of findings: reproducibility, impact, prerequisites and realistic exploitation scenarios. False positive elimination, root-cause grouping, scoring and prioritisation.

5
Step 5: Day 6

Reporting & deliverables

Closing meeting presenting results, top risks, quick wins and structural recommendations. Delivery of a detailed executive and technical report.

See our full approach

Test types

From the internet

External penetration test

Conducted from our premises over a standard internet connection, this test assesses the resilience of your internet-facing infrastructure and services against an outside attacker. The objective is to determine whether a remote attacker can compromise your systems without prior access.

  • Web applications & API
  • Exposed network infrastructure
  • Cloud services
  • Authentication & remote access
From the local network

Internal penetration test

Conducted from the client's premises or via an implant deployed on their network, this test simulates an insider threat: malicious employee, phishing-compromised machine, maintenance agent or external consultant. The objective is to assess what an attacker with physical or network access can achieve.

  • Active Directory & internal network
  • Segmentation & lateral movement
  • Workstations & servers
  • Privilege escalation

Deliverables

What you receive

At the end of each engagement, you receive complete documentation enabling your technical and management teams to act with precision.

Executive report

Risk summary, overall criticality level and priority recommendations, designed for decision-makers.

Technical report

Full detail of each vulnerability: proof of exploitation, impact, attack scenario and remediation recommendation.

Debrief meeting

Closing meeting presenting findings, Q&A and a prioritised action plan with your teams.

Optional retest

Post-remediation verification of vulnerabilities to confirm the effectiveness of fixes implemented.

Industries

Sector-specific expertise for your business

Finance & Banking

Pentest for banking and fintech

Credit institutions, neobanks, payment platforms. Our tests cover DORA and PCI-DSS compliance across your sensitive financial applications and flows.

Healthcare

Pentest for healthcare providers

Healthcare data providers, hospitals, medical software vendors. Tests tailored to HDS certification requirements and patient data protection obligations.

SaaS & Tech

Pentest for SaaS and tech startups

Web apps, REST APIs, cloud infrastructure, CI/CD pipelines. We help software vendors validate their security posture ahead of each release.

Paris & France

On-site engagements across France

Our Paris-based team can travel on-site for internal network tests, Red Team missions or debrief sessions with your technical teams.

Frequently asked questions

Web pentest: what to know before you start

How long does a web application pentest take?

Duration depends on scope: the number of endpoints, user roles and sensitive features. A mid-sized application usually requires five to ten days of testing. We calibrate the effort during scoping, once we have counted the user journeys and account types to cover.

Do we need to provide access and source code?

It depends on the chosen approach. In black box, we start with no privileged information. In grey box, the most common approach, you provide test accounts for each role, which lets us cover access control in depth. In white box, access to the source code sharpens the search for flaws. We usually recommend grey box for the best coverage-to-duration ratio.

How is this different from an automated vulnerability scan?

A scanner detects known patterns: outdated versions, missing headers, signatures of published vulnerabilities. It understands neither your business logic nor your authorisation rules, and cannot chain several minor flaws into a full compromise. We use tooling for coverage, then manual exploitation for the IDORs, workflow bypasses and privilege escalations that no scanner finds.

Ready to assess your exposure?

Our experts define the scope with you and provide a tailored quote within 48 hours.