Internal Penetration Test

Project · AppSec · team grey-box

A team grey-box test of a staging web app and its APIs. My part: the access-control findings, each proven with the requests that show it and paired with a fix.

Where systems fail: the seams

The test focused on the joins between authentication, session state and authorisation logic, including tenant boundaries and file handling.

Who may read what

I took the access-control side: whether one user can reach another user’s records, whether a role check guards every privileged endpoint, and whether a session really ends at logout. Each finding was captured with request/response pairs, its impact and a remediation an engineer could apply.