SQL Injection & Injection Flaws (A03:2021)
We test every input point on your website - forms, URL parameters, headers, cookies, and API endpoints - for SQL, NoSQL, OS command, and LDAP injection vulnerabilities. Our AI fuzzer generates thousands of malformed inputs tailored to your technology stack, detecting both error-based and blind injection flaws that simple scanners miss. SQL injection remains the most exploited web vulnerability worldwide, and a single unpatched form field can expose your entire database.
Blind injection detection Database exposure assessment Cross-Site Scripting (A07:2021)
Comprehensive XSS testing across reflected, stored, and DOM-based variants. We identify locations where user input is rendered without proper sanitisation - enabling attackers to steal session cookies, redirect users to phishing sites, or inject cryptocurrency miners into your pages. Our testing covers modern JavaScript frameworks (React, Vue, Angular) where traditional XSS payloads are filtered but framework-specific bypasses exist.
Reflected, stored & DOM XSS Framework-specific bypasses Content injection testing Authentication & Session Management (A07:2021)
We probe your login mechanisms for credential stuffing resistance, brute force protection, password policy enforcement, multi-factor authentication bypasses, and session token predictability. This includes testing password reset flows for account takeover vulnerabilities, checking JWT implementation for known weaknesses (algorithm confusion, key leakage), and verifying that session tokens are invalidated properly on logout.
Sensitive Data Exposure (A02:2021)
We scan for unintentionally exposed sensitive data - backup files left in web roots, .git directories accessible via browser, API keys embedded in JavaScript bundles, error messages leaking stack traces, and admin panels accessible without authentication. Our crawlers also check for mixed content issues, weak TLS configurations, and missing security headers (HSTS, CSP, X-Frame-Options) that leave your users vulnerable to man-in-the-middle attacks.
Security Misconfiguration (A05:2021)
Default credentials, unnecessary services, verbose error handling, directory listing enabled, outdated software with known CVEs - misconfigurations account for more breaches than sophisticated exploits. We check your web server, application framework, CMS plugins, CDN configuration, and cloud storage buckets for common misconfigurations. This includes WordPress-specific checks (xmlrpc.php abuse, user enumeration, plugin vulnerabilities) for the 35% of Australian business sites running WordPress.
Default credential checks Plugin vulnerability scan Business Logic & Access Control (A01:2021)
Automated scanners cannot test business logic. Our testers manually probe your application workflows - can a standard user access admin functions by manipulating URLs? Can checkout flows be bypassed to get products for free? Can file upload restrictions be circumvented to upload malicious files? Broken access control is now the number one web application security risk according to OWASP, and it requires human reasoning to detect properly.
Privilege escalation testing IDOR vulnerability detection Role-based access validation