Internal Penetration Test
Project · AppSec · team grey-box
A team grey-box test of a staging web app and its APIs. My part: the access-control findings, each proven with the requests that show it and paired with a fix.
- My part Access-control findings
- Scope Staging web app + APIs
- Surfaces Auth · sessions · files · tenant access
- Tooling Burp Suite, manual testing
Where systems fail: the seams
The test focused on the joins between authentication, session state and authorisation logic, including tenant boundaries and file handling.
Who may read what
I took the access-control side: whether one user can reach another user’s records, whether a role check guards every privileged endpoint, and whether a session really ends at logout. Each finding was captured with request/response pairs, its impact and a remediation an engineer could apply.