Back to projectsCybersecurity

Web Application Penetration Test

Problem

A client needed a pre-release security assessment of a customer-facing web application handling sensitive data.

Solution

Conducted a manual penetration test complemented by automated scanning, covering OWASP Top 10, authentication, authorization, and API endpoints.

Architecture

Reconnaissance (Nmap, Amass) → Automated Scan (OWASP ZAP, Nikto) → Manual Exploitation (Burp Suite) → Privilege Escalation → Reporting & Debrief.

Outcome

Identified exploitable vulnerabilities with reproducible steps and severity ratings, enabling the team to fix issues before launch.

Technologies

Burp SuiteOWASP ZAPNmapNiktoMetasploit

Want to see more?

Explore other projects

All Projects