The exact scope depends on your website, hosting setup, technology, and what you want to achieve with the test.
Public Attack Surface: We examine what an outside attacker can discover about your website and its supporting infrastructure. This can include domains, subdomains, publicly exposed services, administrative interfaces, application endpoints, technology fingerprints, and other externally visible components.
Website and CMS Security: Many businesses rely on content management systems such as WordPress, Drupal, Joomla, or other platforms. Tanner Security can evaluate the website platform’s security and identify issues involving old software, vulnerable extensions, unnecessary functionality, insecure configuration, exposed administrative features, and other weaknesses within the approved scope.
Plugins, Extensions, and Components: Third-party plugins, modules, themes, libraries, and other components can expand your website’s attack surface. We examine applicable components for known vulnerabilities, insecure configurations, unnecessary exposure, and other weaknesses that could provide an attacker with an entry point.
Administrative Interfaces: Administrative functions represent an attractive target because successful access can give an attacker significant control over website content, configuration, users, or connected services. We evaluate externally accessible administrative interfaces and the controls that protect them.
TLS and Website Encryption: We examine the website’s use of HTTPS and related encryption configuration within the testing scope. Weak encryption settings or certificate issues can cause security and trust problems, especially if your website handles sensitive information.
Security Headers and Browser Protections: Website security depends partly on how browsers handle content and connections. Tanner Security can evaluate applicable HTTP security headers and browser-facing protections that help reduce risks such as content injection, framing attacks, and other browser-based abuse.
Public Files and Information Exposure: We look for files, directories, backups, configuration information, metadata, comments, or other publicly accessible resources that could reveal information an attacker could use. A website doesn’t need a big vulnerability to leak useful information. Sometimes, a few small issues together can give an attacker enough information to launch a bigger attack.
Server and Application Configuration: We examine security-relevant configuration exposed through the website and its supporting services. Depending on the environment, this can include unnecessary services, debugging information, directory listings, default configurations, exposed management functions, and other weaknesses.
Input and Interactive Functions: When the website accepts user input, we test applicable functions for issues such as injection, cross-site scripting, file-handling weaknesses, and other externally exploitable vulnerabilities. When those functions cover complex application logic, Tanner Security can expand the scope into a full web application penetration test.