Web applications are increasingly critical to business operations and, at the same time, increasingly exposed to attacks. Many vulnerabilities stem from improper input handling and insufficient controls during development.
Penetration testing on web applications simulates a real attack: it verifies the underlying infrastructure, analyzes entry points, and attempts to achieve the deepest possible compromise. This article illustrates representative cases where OWASP Top Ten vulnerabilities were identified and resolved through penetration testing activities.
1. SQL Injection in an e-commerce application
Injection flaws (OWASP A03)
Injection vulnerabilities occur when untrusted data is sent to an interpreter as part of a command or query. In the case of SQL Injection, an attacker can execute unauthorized commands on the database or access confidential data.
Discovery via penetration test
During a penetration test on an e-commerce application, input fields — the search bar and login form — were found to be vulnerable to SQL injection. By injecting malicious SQL code, the tester was able to bypass authentication, retrieve sensitive customer data, and modify product prices.
Example of exploit
In the username field of a login form, entering ' OR '1'='1 exploits the SQL query logic to bypass the credential check.
Solutions adopted
- Input validation: allow only expected characters and formats, rejecting everything else.
- Parameterized queries (prepared statements): user input is treated as data, not as executable code.
- Principle of least privilege: limit database user permissions to the minimum necessary for the application to function.
The application thus prevented potential data breaches and protected customer information.
2. Cross-Site Scripting in a banking application
XSS (OWASP A07)
XSS vulnerabilities occur when a web application includes untrusted data in a response sent to the browser. An attacker can execute malicious scripts in the victim’s browser context, steal sessions, perform defacement, or redirect users to malicious sites.
Discovery via penetration test
The application’s message board did not properly sanitize user input. An attacker could inject malicious JavaScript code into a message, which was then executed in the browser of anyone viewing that section.
Example of exploit
- The attacker posts a message containing JavaScript code designed to steal session cookies or redirect the user to a phishing site.
- When another user views the message, the code is executed in their browser.
Solutions adopted
- Output encoding: encode all user-provided output before rendering it in the browser.
- Contextual escaping: apply escaping techniques based on the display context (HTML, JavaScript, URL).
- Content Security Policy (CSP): implement a strict policy to control the resources that the browser can load.
The banking application thus protected user sessions and prevented unauthorized access.
Other OWASP Top Ten vulnerabilities to consider
SQL Injection and XSS are among the most widespread, but the OWASP Top Ten covers a broader set of risks that every penetration testing program should address:
- Broken Authentication: implement multi-factor authentication, robust password policies, and proper session management.
- Security Misconfiguration: correctly configure applications, frameworks, servers, and databases, while maintaining all security updates.
- Insecure Direct Object References (IDOR): implement access controls to prevent direct access to resources based on user input.
- Broken Function Level Access Control: verify user authorization on the server side for every exposed feature.
- Cross-Site Request Forgery (CSRF): use anti-CSRF tokens to prevent unwanted actions performed on behalf of the authenticated user.
- Vulnerable and Outdated Components: regularly update libraries, frameworks, and dependencies to fix publicly known vulnerabilities.
- Unvalidated Redirects and Forwards: validate and sanitize user input to prevent redirects to malicious sites.
What these cases teach us
- Proactive security: regular penetration testing allows for identifying vulnerabilities before they are exploited in production.
- Defense in depth: no single control is sufficient; the combination of multiple measures significantly reduces the attack surface.
- Continuous monitoring: web applications evolve; security controls must evolve with them.
- Developer training: awareness of common vulnerabilities reduces the number of flaws introduced during development.
- Regulatory compliance: penetration testing is often required by standards such as PCI DSS, ISO/IEC 27001, and the NIS2 directive.
Frequently Asked Questions
- What is the OWASP Top Ten and why is it relevant for penetration testing?
- The OWASP Top Ten is a reference document that lists the ten most critical vulnerability categories for web applications, updated periodically by the OWASP community. It forms the methodological basis of many penetration testing programs because it covers the most statistically frequent and high-impact risks.
- How often should a penetration test be performed on a web application?
- The frequency depends on the context: in general, at least an annual test is recommended, but also after every significant release, infrastructure modifications, or changes in compliance requirements. Standards like PCI DSS impose specific cadences.
- What is the difference between vulnerability assessment and penetration testing?
- Vulnerability assessment identifies and classifies vulnerabilities present in a system, without necessarily exploiting them. Penetration testing goes further: it actively attempts to exploit vulnerabilities to assess the real impact and the depth of compromise reachable by an attacker.
- Do OWASP Top Ten vulnerabilities only concern web applications?
- The OWASP Top Ten was created for web applications, but many of the principles — such as input validation, access control, and secure session management — also apply to APIs, mobile applications, and microservices. OWASP also publishes dedicated lists for these contexts.
- What happens after a penetration test: how is remediation managed?
- At the end of the test, a report is produced that classifies vulnerabilities by severity and includes operational recommendations. The development team or application provider implements the fixes, after which it is good practice to perform a retest to verify that the vulnerabilities have actually been resolved.
Useful resources
- Web Application Penetration Testing — how ISGroup verifies the security of web applications by simulating a real attacker.
- Guide to penetration testing for web applications — how to turn OWASP risks into operational testing activities.
- The role of a specialized partner in WAPT — criteria for choosing who should perform tests, reports, and remediation.
- Network Penetration Testing — manual verification of IT infrastructure to identify critical issues that automated scanners do not detect.
- Vulnerability Assessment — non-invasive activities to identify known vulnerabilities and maintain a high level of security.
- Code Review — source code analysis to identify vulnerabilities not surfaced during dynamic testing.
- Ethical Hacking — simulation of complex attacks involving infrastructure, people, and physical security.
- Training — practical paths for developers and security teams on secure coding and OWASP best practices.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
