Web Application Penetration Testing

A senior tester manually attacks your application the way a real adversary would — authentication, access control, business logic and everything in between. You get findings that matter, with reproduction steps your engineers can act on the same day.

What is a web application penetration test?

A web application penetration test is a time-boxed, authorised attack on your application by a skilled human tester. Unlike automated vulnerability scans, a penetration test exercises the parts of your application that tools can't reason about: multi-step business logic, authorisation between roles and tenants, payment and workflow abuse, and chained vulnerabilities that only matter in combination.

At the end you receive a report with an executive summary, technical findings with evidence and reproduction steps, remediation guidance, and a free retest of fixed issues within 90 days.

What we test

  • Authentication & session management. Login flows, MFA, password reset, OAuth/SSO integrations, token handling and session fixation.
  • Authorisation & access control. Privilege escalation between roles, cross-tenant data access (IDOR/BOLA), and the admin functionality you forgot was exposed.
  • Business logic. Race conditions, workflow bypasses, price and quantity manipulation — the bugs only a human finds.
  • Injection & classic vulnerability classes. SQL/NoSQL injection, XSS, SSRF, XXE, deserialisation, file upload abuse and the rest of the OWASP Top 10.
  • Modern stacks. Single-page apps, GraphQL and REST backends, WebSockets, and the third-party integrations that quietly expand your attack surface.

How an engagement runs

We start with a free 30-minute scoping call and give you a fixed quote within one business day. Most web application tests run 5–10 testing days depending on the size and complexity of the application. During testing we keep an open channel with your team — critical findings are escalated the moment we find them, not two weeks later in a PDF.

Testing is aligned with the OWASP Web Security Testing Guide, but driven by experience: every Ironbark engagement is performed hands-on by a senior tester with a track record in bug bounty programs and offensive security research.

Built for compliance, designed for security

Our reports are written to satisfy ISO 27001, SOC 2, PCI DSS and customer security questionnaires — but the testing itself is built to find real attack paths, not to tick a box. If you need a pentest for certification, see our ISO 27001 penetration testing page.

FAQ

Frequently asked questions

How much does a web application penetration test cost?

Most web application penetration tests run 5–10 testing days. As a guide, a focused single-application test typically lands between AU$8,000 and AU$18,000 depending on size and complexity. We provide a fixed quote within one business day of a scoping call, and the price never changes mid-engagement.

How long does a web application penetration test take?

Typically 1–2 weeks of testing, with the report delivered within a week of testing finishing. Critical findings are communicated immediately during the engagement, so you never wait for the report to start fixing the things that matter.

Is a penetration test the same as a vulnerability scan?

No. A vulnerability scan is an automated tool that flags known issues, with significant false positives and no understanding of your business logic. A penetration test is a human expert actively attacking your application, chaining issues together and validating real-world impact. Scans are a useful hygiene measure; penetration tests find the bugs that lead to breaches.

Do you test in production or staging?

Either. Many clients prefer a staging environment that mirrors production. When we test production systems, we agree on rules of engagement up front and test carefully — we've done this for organisations of every size without disruption.

What do we receive at the end of the test?

An executive summary for non-technical stakeholders, a technical report with evidence, reproduction steps and remediation guidance for every finding, a debrief call with your engineering team, and a free retest of fixed issues within 90 days.

Will the report satisfy our auditors and enterprise customers?

Yes. Our reports are regularly used for ISO 27001 and SOC 2 audits, due diligence processes and enterprise customer security reviews. We include an attestation letter you can share externally without exposing the technical details.

Contact

Talk to us

Tell us what you're trying to protect, secure or build. We'll come back with a plan.

Prefer to talk live? Book a call →

By submitting this form, you agree to our privacy policy.

Ready to test your application?

Drop your email and we'll come back with a plan within one business day.