Sample report · Web & mobile application assessment

Web & Mobile Application Assessment

A security assessment of web and mobile applications and their supporting APIs — the business-logic and access-control flaws a scanner never reaches.

What happened

By manipulating identifiers in API requests, OSec read other users’ account data and balances; the MFA flow allowed full API access before the second factor was ever completed. One high-risk finding, five medium.

Scope. Web and mobile applications and the APIs behind them — access control, session handling, and client-side protections.

What’s inside

The report, section by section

  1. Executive summary
  2. Scope
  3. Methodology
  4. Findings summary
  5. Findings (with reproduction)
  6. Conclusion

The findings

  • MFA bypass
  • Insecure direct object reference (IDOR)
  • Bypass of session security controls
  • Sensitive information disclosure
  • Account enumeration using application error
  • Unsanitised file upload

Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.

The document

Preview the report. Unlock the whole thing.

Unlock the full report ↓

The opening pages are free to read. Unlock the full 30-page report →

Unlock it

The full report here, plus all three as PDFs.

Drop your work email: the preview above unlocks to the full document, and we’ll send this report plus the other two as downloadable PDFs.

We’ll email the download links to that address.