WEB APPLICATIONS
and APIS
-
Server and Clientside
FrameworksWe’ve been manually auditing applications and APIs since before the modern web. The new frontier of security involves logical bugs, prototype pollution, API path traversal, broken state machines, second-order injections, misuse of libraries, inconsistencies between the application and the cloud infrastructure and many other novel techniques.
The progressive shift to SecDevOps and tech stacks that are secure-by-default have significantly changed the type of vulnerabilities and misconfigurations that affect mainstream web applications. Despite that, Doyensec will understand the goals and needs of the application to find ways of breaking the assumed control flow.
Our methodology combines source code review with dynamic testing to deliver effective and efficient security auditing. We strongly encourage our clients to provide source code during security testing activities, however we are comfortable with traditional black-box testing. When auditing web applications and APIs, we build a profile of the assets and methodically attack and track each form of input into the application. We detail how users interact with the system and model potential oversights with use and availability.
-
manual testing and
custom toolingWe intercept and inspect each request and response between client and endpoint. We find well-known bug classes including Cross-Site Scripting, SQL injection, Cross-Site Request Forgery, Command Execution, Path Traversal and many more.
We seek a deeper understanding of the application in order to find unexpected flaws such as business logic bugs or undisclosed vulnerabilities in the application dependencies.
Findings are reported and prioritized by severity with clear remediation steps. We will find bugs, but that is just the first step in the process.
our research articles
Research is one of our founding principles and we invest in it heavily. All of our researchers have the privilege to use 25% of their time exclusively for self-directed research.
show more publications