    When people think about web application testing, they foremost think of having their public website tested. A web application penetration test can help answer this question. While that is definitely important, there are many other web applications that should be considered for testing, including: customer / user portals, support sites, employee portals, custom web sites, web services, web based email systems, SSL VPN solutions, etc. The goal is very similar to that of an external network pen test: to identify vulnerabilities in the web application itself; identify vulnerabilities in related devices; and then gain access to the systems and / or sensitive data.

