Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find website vulnerabilities with an authorized, repeatable security test: define written scope, map the application as a normal user, validate controls across unauthenticated and authenticated attack surfaces, preserve reproducible evidence, assess impact, give the owner a technical fix, and retest after remediation. OWASP defines a security test as “a methodically validating and verifying” of application-security controls; a vulnerability is a weakness in design, implementation, operation or management that can be exploited against a security objective.

1. Get permission and define exactly what you may test

Only test systems you own or for which you have explicit written authorization. A production domain, staging host, API, mobile endpoint, cloud bucket, and third-party integration should each be named in the rules of engagement. Authorization should also state the test window, source IPs, allowed accounts, prohibited actions, emergency contact, data-handling rules, and whether automated scanning is permitted.

Write a scope sheet

  • Targets: hostnames, URL paths, API base URLs, IP ranges and environments.
  • Accounts: test users for every role, including a least-privilege user and an administrator supplied by the owner.
  • Exclusions: payment processors, third-party SaaS, employee accounts, destructive functions and denial-of-service activity unless specifically approved.
  • Stop conditions: data corruption, access to real customer data, service instability or evidence of an active compromise.
  • Evidence rules: what may be stored, where it is encrypted, and when it will be deleted.

If you cannot establish these boundaries, stop at passive observation and request authorization rather than probing a public site.

2. Map the application passively before changing anything

OWASP’s methodology starts by understanding the application as an end user. Browse normal journeys without submitting unexpected data or altering records. Build an inventory of pages, API calls, roles, cookies, redirects, error responses, file uploads, and state-changing actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Follow every normal user journey

  1. Start unauthenticated: home page, registration, login, password reset, search and public files.
  2. Sign in as each approved role and record what that role can see and do.
  3. Trace workflows such as checkout, profile changes, approvals, exports and account deletion.
  4. Record requests made by the browser, including method, path, parameters, content type, cookies and anti-CSRF tokens.
  5. Note technology clues, security headers, cache behavior, verbose errors and differences between HTTP and HTTPS.

Passive mapping gives you a model of intended behavior. It also prevents a common testing error: treating a valid business workflow as an isolated URL and missing the authorization checks around it.

3. Choose a test model and coverage

Black-box testing assumes little or no prior information, while a source-assisted or architecture-assisted review uses documentation, code or deployment details supplied by the owner. Neither model is automatically more thorough; coverage depends on which roles, interfaces and controls are actually exercised.

Dimension Black-box test Source or architecture-assisted test
Information Public behavior, approved accounts and observed traffic May include source, diagrams, API specifications and deployment configuration
Strength Shows what an external attacker can discover Reveals unreachable code paths, trust boundaries and unsafe defaults earlier
Blind spot Internal paths and dead code may remain unseen May miss real-world discovery and operational mistakes if external behavior is not tested
Best use External attack-surface validation Defense-in-depth review combined with external testing

Use both passive observation and active validation. Keep the modes separate in your notes because active requests may create records, trigger notifications or consume one-time tokens.

4. Test the controls that protect accounts and data

Configuration and deployment management

  • Check that HTTPS is enforced and certificates are valid for every approved hostname.
  • Review security headers, cookie flags, cross-origin policy, cache controls and directory or debug exposure.
  • Look for development consoles, backup archives, source maps, default credentials and detailed stack traces.
  • Confirm that production secrets are not embedded in client JavaScript, HTML or downloadable configuration files.

Identity management

Test registration, account linking, email or phone changes, password reset and account recovery. Verify that identity proofing and recovery steps do not let one user attach another user’s identifier. Check rate limits and notification behavior with test accounts; do not attempt credential stuffing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authentication

  • Confirm passwords are not accepted over an unintended insecure channel.
  • Verify multi-factor enrollment, challenge, backup-code and factor-removal flows.
  • Check login throttling, lockout recovery and consistent error messages without causing an outage.
  • After logout, password change or account disablement, verify that old sessions and tokens cannot continue to access protected functions.

Authorization

For every sensitive request, test both horizontal access (user A accessing user B’s object) and vertical access (a lower-privilege role invoking an administrator function). Use two approved accounts and harmless records. Change only identifiers that the owner has designated for testing, and stop if real data appears.

Session management

Inspect session creation, rotation after login, expiry, idle timeout, concurrent sessions, refresh tokens and cookie attributes. A session identifier should not remain valid after the events the application promises will invalidate it. Check that tokens are scoped to the correct audience and cannot be replayed in another context.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Input handling and output encoding

Inventory every input: query parameters, JSON fields, form values, headers, file names and imported data. Validate type, length, format and allowed values on the server. In a controlled test environment, submit benign boundary values and verify that the application returns a safe validation error rather than a stack trace, interpreted markup or an unexpected query result. Confirm that output is encoded for its actual context (HTML, JavaScript, URL, SQL, template or shell) and that file uploads enforce type, size, storage and execution rules.

Business logic and workflow controls

Security bugs often arise between individually valid steps. Test whether a user can skip approval, repeat a one-time action, alter a price or quantity after authorization, reuse a completed token, or perform steps out of order. Define expected invariants with the owner, then verify them using test data and normal-rate requests.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

APIs and data exposure

Apply the same identity, authorization, validation and rate-limit checks to JSON, GraphQL, webhook and background-job endpoints as to the visible website. Compare fields returned to each role, pagination boundaries, export functions and error messages. Ensure logs, analytics payloads and client-side state do not expose secrets or unnecessary personal data.

5. Preserve evidence that another person can reproduce

Each finding should stand on its own. Capture the smallest safe sequence that demonstrates the issue and redact secrets and personal information.

Field What to record
Title and location A concise description, affected URL or endpoint, HTTP method and parameter or component
Preconditions Environment, role, account state, feature flags and required setup
Steps Numbered requests or UI actions, with sensitive values replaced by placeholders
Expected versus observed The security control that should apply and the behavior actually seen
Impact What confidentiality, integrity, availability or account boundary is affected
Evidence Sanitized request/response excerpts, timestamps, screenshots, logs or video
Fix and retest A technical mitigation, owner, status and the exact check to repeat

A screenshot can document a visible state, but it should supplement—not replace—the request, response and authorization context. Hash or otherwise preserve evidence according to the engagement’s chain-of-custody rules.

6. Rate impact and recommend a technical fix

Describe practical consequences rather than assigning a label without explanation. State who can exploit the issue, what access is required, what data or action is reachable, whether exploitation is repeatable, and whether monitoring would detect it. Give a concrete mitigation: enforce server-side authorization, rotate or invalidate tokens, encode output in the correct context, remove debug artifacts, constrain uploads, or add workflow state checks. Include compensating controls only when the primary fix cannot be deployed immediately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Deliver findings to the system owner, not to unrelated parties. Coordinate disclosure, protect the report, and agree on a due date. Retest the exact affected path after the fix, then test nearby variants so a narrow patch does not leave the same control missing elsewhere.

7. Use OWASP as a repeatable checklist, not a guarantee

The OWASP Web Security Testing Guide organizes testing around methodical validation and verification. Its developer guidance includes configuration and deployment management, identity management, authentication, authorization and session management. Expand that framework for the application’s APIs, business workflows, data exposure and deployment architecture. It is a starting structure, not a promise that every possible defect is enumerated.

The guide’s release history records version 4.2 on December 3, 2020, with a printed book associated with version 4.0. Treat those as dated release facts; verify the current project status and edition before purchasing or citing a newer version.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Capture clean visual evidence without hiding test context

When a finding depends on what a user sees, capture the page after the authorized test action. Preserve the URL, role, timestamp and request evidence alongside the image. Remove personal data before sharing the report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and responses identify the result with X-Page-Verdict and X-Billed headers. An MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.

Use the API documentation at https://screenshotneo.com/docs/ for authentication and options. Replace the target URL only with an authorized page.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

For security evidence, useful options include full-page capture with lazy images loaded, a CSS-selector element capture, a chosen device or viewport, retina scale, dark mode, custom CSS or JavaScript, a click before capture, selector or network-idle waits, hidden selectors, blocked requests or resource types, custom headers, cookies, user agent, Authorization, timezone and geolocation, transparent backgrounds, resizing, a chosen cache TTL, signed links, asynchronous jobs with signed webhooks, PDF page ranges and bulk capture of up to 100 URLs per call. Do not put secrets in a public signed link or expose an authorization header in a screenshot URL.

Rank #4
Fluke Networks 10660001 Security Key Insert for Can Wrenches
  • Reversible insert tool for can wrenches.
  • One end for SLC Cabinets. Other end for pin in head screws found in most Network Interface boxes.

Plans are Free: 1,000 shots per month with no card; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; and Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Create a free ScreenshotNeo account to get 1,000 screenshots a month without a card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Troubleshoot common testing problems

The application blocks your test account

Confirm the account is approved, the source IP is allow-listed and the environment matches the authorization. Do not bypass a control; ask the owner to adjust the test setup.

Responses differ between browser and API client

Compare cookies, CSRF tokens, authorization headers, content type, redirects, user agent and required origin or referer behavior. Reproduce one request at a time and document the difference.

A scanner reports many uncertain findings

Triage manually against the intended workflow. Confirm exploitability with harmless data, remove duplicates, and report only evidence-backed issues with an owner-facing fix.

Your evidence contains sensitive data

Stop collection, notify the designated contact, restrict access, redact copies and follow the agreed retention and deletion procedure. Never paste secrets into a public ticket or screenshot URL.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A ScreenshotNeo capture is blank or challenged

Check the response’s X-Page-Verdict and X-Billed headers, then use an appropriate wait condition, viewport, cookie, user agent or authorized header. A bot check, blank page, timeout or failed load is not billed; correct the target or test setup before relying on the image as evidence.

10. A practical completion checklist

  • Written authorization and scope are stored with the engagement.
  • Unauthenticated, authenticated and administrative journeys are mapped.
  • Configuration, identity, authentication, authorization, session, input, workflow, API and data-exposure controls are covered as applicable.
  • Every finding has reproducible steps, sanitized evidence, impact and a technical remediation.
  • Findings are delivered securely to the owner with severity rationale and deadlines.
  • Fixes are retested, adjacent variants checked and final evidence retained according to policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.