Web Application Pentest
Authentifizierung, Autorisierung und Business-Logic. Wir prüfen Flows, die Scanner nicht sehen: GraphQL-Alias-Angriffe und Introspection-Smuggling, Rate-Limit-Bypass über Aliasing, Session-Rotation-Lücken, Cross-Tenant-IDOR, CORS-Konfigurations-Drifts.
Deliverable
Executive-Summary + detailliertes Finding-Report mit CVSS 3.1, Proof-of-Concept pro Finding, Remediation-Empfehlung, Re-Test nach Fix.