An online banking platform required a manual penetration test of their customer-facing web application and APIs to satisfy regulatory expectations and internal risk management. They needed OWASP Top 10 coverage plus business-logic and authentication/session testing.
Scope: Online banking web app (login, dashboard, transfers, statements, profile); REST APIs for mobile and web. Out of scope: core banking backend, third-party payment gateways (black-box only). Success criteria: OWASP Top 10 and business logic tested; critical/high findings remediated with retest. Rules of engagement: testing from approved IPs; no DoS; credentials provided for authenticated testing.
Manual testing following OWASP Testing Guide and PTES. Test cases included:
| Category | Test Cases Performed |
|---|---|
| Authentication | Brute force, lockout, password policy, MFA bypass, session fixation, logout |
| Authorization | IDOR (accounts, transactions), privilege escalation, path traversal |
| Injection | SQL, XSS (reflected/stored), command injection in search/admin |
| Business logic | Transfer limits, negative amounts, concurrent transactions, replay |
| Session | Token strength, timeout, concurrent sessions, cookie flags |
Tools: Burp Suite Pro, custom scripts. Standards: OWASP Top 10, PTES, NIST.
19 findings (3 critical, 6 high, 7 medium, 3 low). Critical included:
Remediation support included exact fix recommendations and retest; all critical and high were fixed within 3 weeks.
We provided step-by-step remediation guidance and performed a full retest after fixes. Results: 100% of critical and high findings remediated; residual medium/low tracked in client's backlog. Client satisfied with clarity of findings and actionable recommendations.
"The most thorough pen test we have had. Findings were clearly documented and fixable."— Security Lead, Online Banking
Business logic testing required manual exploration and abuse-case design. For similar organizations: include APIs and mobile-backend in scope; plan for at least one retest; align success criteria with regulators early.
Get a free security assessment and see how we can bring your security posture to manageable levels.