Web & Mobile Application Assessment
A security assessment of web and mobile applications and their supporting APIs — the business-logic and access-control flaws a scanner never reaches.
By manipulating identifiers in API requests, OSec read other users’ account data and balances; the MFA flow allowed full API access before the second factor was ever completed. One high-risk finding, five medium.
Scope. Web and mobile applications and the APIs behind them — access control, session handling, and client-side protections.
The report, section by section
- Executive summary
- Scope
- Methodology
- Findings summary
- Findings (with reproduction)
- Conclusion
The findings
- MFA bypass
- Insecure direct object reference (IDOR)
- Bypass of session security controls
- Sensitive information disclosure
- Account enumeration using application error
- Unsanitised file upload
Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.
Read the full redacted report.
PDF not showing? Get a downloadable copy →
Get the PDF, plus all three sample reports.
You’ve read it here. Drop your email and we’ll send this report, plus the other two, as downloadable PDFs.