A webshop is a more attractive target for attackers than most businesses realise: payment data, customer data, and often a connection to inventory and logistics systems are all at stake, and the barrier to abusing a vulnerability is low as soon as someone can simply log in as a customer. A pentest for e-commerce therefore differs from a regular web application pentest in a number of specific ways.
Payment data: PCI DSS is not optional
As soon as a webshop processes, stores or transmits card data, it falls under PCI DSS. Under version 4.0, that means at least annual internal and external penetration tests, plus a retest after every significant change to infrastructure or applications within the cardholder data environment. Most webshops use an external payment provider so they don’t have to store card data themselves, which reduces the scope but doesn’t eliminate it: the integration with that provider, how amounts are passed through and validated, and whether it’s possible to manipulate a finalised amount before it’s sent to the payment provider, remain important test points. See our PCI DSS pentest page for the full scope.
Business logic around pricing, discounts and inventory
Webshops have their own category of vulnerabilities that have little to do with classic technical hacks, and everything to do with bypassing business rules:
- Can you use a discount code multiple times, or combine codes when that isn’t intended?
- Is it possible to manipulate a product’s price between the shopping cart and final checkout?
- Can you reserve or block inventory by placing orders and never completing them?
- Can discount rules and gift vouchers be combined in ways that cause financial loss?
An automated scanner rarely finds this type of vulnerability; it requires a tester who actually walks through the webshop both as a customer and as an attacker.
Customer accounts as an attack vector
With hundreds to millions of customer accounts, a webshop is a prime target for credential stuffing: attackers trying leaked passwords from other sites on your platform. A pentest therefore routinely looks at rate limiting on login attempts, whether accounts leak information (for example, whether an error message reveals that an email address already exists), and whether personal order history and address details are properly isolated between customers.
Peak moments call for a different test timing
Many webshops generate their biggest revenue around specific peak moments such as Black Friday or the holiday season. A pentest shortly before such a peak period, rather than at some random point in the year, ensures that exactly the systems under the heaviest load and most attractive for abuse are tested with extra scrutiny. Do plan in time, though: a thorough pentest and the time to fix findings take weeks, not days.
A real-world example
In a recent engagement, it turned out to be possible to adjust an order’s total price during checkout by modifying a hidden form field in the browser right before payment was initiated. The payment provider itself processed the (manipulated) amount correctly — the problem wasn’t there, but in the webshop, which didn’t re-validate the amount before forwarding it to the provider. On paper, “the payment” was therefore technically processed correctly, while the webshop could in fact be checked out for a self-chosen amount. This exact kind of vulnerability, at the intersection of technology and business logic, is what a targeted e-commerce pentest is for.
How MonkeysICT tests e-commerce platforms
Alongside regular web application security, we always explicitly test business logic around pricing, discounts and inventory, and include the integration with your payment provider in the scope. That gives a more realistic picture of the risk than a test that only looks at technical vulnerabilities.
