forumNew topic

We're getting a web app pentest done but want to prep first — is there a checklist we can run through ourselves?

GGürkan Y***Member
Job title
Secretary
Sector
Real estate
Organization type
300-person organization
Joined
Jun 2022
Message
85
#1

We're a 6-person engineering team developing enterprise logistics software based in London. Ahead of signing an integration contract with a major freight company we need to get an independent web app pentest done for our web application. We got a quote from an independent testing firm for £4,500 for a 5-day engagement, and the test is scheduled to start in three weeks.

Since our budget is tight, we want those 5 days to be spent as efficiently as possible. We don't want the testers wasting their time on trivial stuff like missing headers or default passwords; we want them to focus on the business logic and authorization architecture.

Is there a practical prep checklist we can go through internally before the test kicks off? What basic checks should we as developers complete before handing the environment over?

AAyberkExpert
Job title
Mobile developer
Joined
Jul 2023
Message
208
Most Helpful#2

Short answer: The main goal of pre-pentest prep is to clear out surface-level configuration flaws that automated tools can sniff out in seconds, freeing up the tester's time for in-depth business logic assessments. Proper prep both maximizes the value you get from the test and keeps the final report from being bloated with low-impact findings.

Here are the checklist steps you can run with your own team: 1) Authentication and access control: Set up at least two test users per role and manually verify that one user can't access another's data just by changing IDs (object-level access control). 2) Dependency and library scanning: Run internal tools that scan your repo's open-source packages for known vulnerabilities, and apply up-to-date patches. 3) Error handling and data leaks: Turn off detailed server error messages (stack traces) in both staging and production, and make sure API responses aren't returning unnecessary database fields. 4) HTTP security headers and cookie flags: Confirm that the secure and httponly flags are set on all cookies.

Finally, don't forget to prep the test environment. Provide the testers with up-to-date documentation covering every API endpoint, and whitelist their IP address in your firewall. Otherwise, they'll spend half of day one blocked by your WAF, burning valuable time.

TTülay A***Member
Job title
Store associate
Sector
Packaging
Organization type
8-person team
Joined
Dec 2023
Message
64
#3

Last year we paid £5,000 for a pentest on a similar B2B app. Because we didn't do any prep, 14 out of the 22 findings in the report were just missing HTTP headers and default server banners. It was painful realizing at least £1,500 worth of the consultant's time went into reporting complete basics.

GGökhan C***Member
Job title
Purchasing manager
Sector
Printing
Organization type
medium-sized business
Joined
Jun 2022
Message
181
#4

The single most critical thing is environment stability. Never point them at production; set up a dedicated staging server seeded with an anonymized dump of real data. That way, when the tester runs payloads that corrupt the DB or flood your queues, live operations won't go down. Also, put a strict deploy freeze on the staging environment for the entire duration of the test.

YYağmur C***MemberCommunity member
Joined
May 2023
Message
274
#5

Double-check input validation and cryptography. Make sure special characters are properly escaped across all form inputs and URL parameters. Ensure every piece of user input saved to the database is sanitized, and confirm session tokens are properly invalidated server-side upon logout. Gaps in these areas will immediately drag down your test results.

HHalil S***Member
Job title
General Manager
Sector
Textile
Organization type
medium-sized business
Joined
Aug 2024
Message
242

Doki · Server maintenance contract · 2023

#6

Don't oversimplify the staging setup trying to make everything friction-free. Sometimes devs drop the firewall completely or turn off protection layers just to make the testers' lives easier. Then the app gets a clean report, goes live, and gets hacked immediately. The test environment must be a 1:1 mirror of production.

BBerkMember
Job title
Real Estate Agent
Joined
Apr 2024
Message
102

Doki · Incident response support · 2026

#7

Give the testers two valid accounts for each role: two standard users and two admins. Also throw in a demo account with strictly limited permissions. That allows them to test privilege escalation and IDOR horizontally between users right from hour one without roadblocks.

MMehmet Y***Member
Job title
IT manager
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Oct 2024
Message
4
#8

Is your scope white-box or black-box? If you're handing over source code and API schemas closing documentation gaps should be your top priority during prep. If you aren't giving them code access put all your focus on hardening externally exposed endpoints.

VVolkan A***Expert
Job title
Operations director
Sector
Jewelry
Organization type
cooperative
Joined
Nov 2022
Message
314
#9

You have the exact right mindset here. Doing your own prep also massively levels up the dev team's security awareness. If you run a half-day internal workshop to review the OWASP Top 10 directly against your codebase, you'll get the absolute most out of the engagement.

NNuri U***VeteranCommunity member
Joined
Feb 2024
Message
325
#10

definitely whitelist their ip on the firewall. during our pentest the tester got blocked completely on day one and they wasted half a day sending emails back and forth just to get unbanned, total waste of money.

LLevent Y***VeteranCommunity member
Joined
Jun 2023
Message
128
#11

I agree.

DDamla K***MemberCommunity member
Joined
Aug 2025
Message
1
#12

The opposite happened to me, that's why I'm writing. Solutions that work at a small scale collapse when you grow; I learned this late.

The harder it is to reverse a decision the slower you should make it. Proven by experience.

KKübra G***Expert
Job title
IT manager
Sector
Sports and fitness
Organization type
20-person company
Joined
Nov 2025
Message
10
#13

If you're going this route, sort this out first. Processes without records never improve, because you don't know what to fix.

This is my opinion, I'm not claiming it's absolute truth.

SSerkan B***MemberCommunity member
Joined
Mar 2025
Message
53
#14

Let me summarize what's been said so far. An automated scan report is not the same as a penetration test.

Good luck with that.

MMerve K***Member
Job title
Clinic manager
Sector
Agriculture
Organization type
sole proprietorship
Joined
Jul 2023
Message
127

Doki · Phishing awareness training · 2024

#15

This thread is archived.

JJülide A***Member
Job title
Accounting Manager
Sector
Jewelry
Organization type
20-person company
Joined
May 2024
Message
103

Doki · Vulnerability scanning · 2026

#16

Heres how it went for us. If you dont write this down from the start it leads to arguments later.

Forgotten test environments are more often the entry point than live systems. If you post the result here, it will help others too.

NNecati T***Member
Job title
Chief Technology Officer
Sector
Healthcare services
Organization type
two-branch business
Joined
Nov 2025
Message
82

Doki · Brand identity · 2026

#17

I think differently. When we decide without measuring, we always end up in the same place.

An untested backup is not a backup. If you have questions, write them; I'll answer as best I can.

TTuğçe O***MemberCommunity member
Joined
Sep 2025
Message
3
#18

I have no experience with web app pentest, so I'm asking. Having backups accessible on the same network and with the same identity makes them part of the target.

If you have questions, write them; I'll answer as best I can.

DDoruk T***MemberCommunity member
Joined
Jul 2023
Message
23
#19

Timely topic.

İİlknur A***MemberCommunity member
Joined
Jan 2024
Message
220
#20

My question might sound amateurish, sorry about that. Most incidents start with a leaked password, not a vulnerability.

Reply