
>_[01 / 06]
Web Application
Auth, authorization, input handling, session management.

Every class chained, every report actionable. We test the things scanners and checklists miss.

Auth, authorization, input handling, session management.

REST and GraphQL. BOLA, mass assignment, exposed endpoints.

Price manipulation, workflow bypass, privilege escalation via app logic.

OAuth, SSO, MFA bypass, account takeover, password reset chains.

Keys in code, exposed configs, sensitive data in responses.

Solidity review. Reentrancy, access control, flash loan vectors.