AttackLedger coverage report
Client web app
Summary
Of 24 possible lanes (2 in-scope hosts × 12 lanes), 6 were opened and 5 are receipted: every checklist item has evidence or a written reason, the receipt matches the ledger, and a named person reviewed the lane and closed it. No receipts are void. Lanes that were not opened were not tested.
What this report proves. It is a record of what was tested, not a judgement of how well. It shows which checklist items were recorded as tested or not applicable, which evidence was attached to each, who closed each lane and when, and that none of this changed after it was recorded: the evidence is hash-chained, signed receipts carry a signature from the reviewer’s own key, timestamped receipts carry a token from an independent timestamp authority, and anyone can re-check all of it offline.
It does not prove that the tests themselves were thorough or correct, that untested lanes or hosts are free of issues, or that a signing key belongs to the person named; compare key fingerprints with the signers for that. It is not a list of findings.
Scope and authorization
The authorization entry is the tester’s own statement that they were permitted to test, with the policy or statement of work it refers to. Recon and agent runs only reach hosts that match these rules, at this rate.
Coverage matrix
Each in-scope host against each lane of the methodology pack.
| Lane | api.client.test | app.client.test |
|---|---|---|
| Information gathering | Receipted | Receipted |
| Configuration | Not opened | Receipted |
| Identity management | Not opened | Not opened |
| Authentication | Not opened | In progress |
| Authorization | Not opened | Receipted |
| Session management | Not opened | Receipted |
| Input validation | Not opened | Not opened |
| Error handling | Not opened | Not opened |
| Cryptography | Not opened | Not opened |
| Business logic | Not opened | Not opened |
| Client side | Not opened | Not opened |
| API | Not opened | Not opened |
| Receipted | 1 of 12 | 4 of 12 |
Receipts
A receipt is the SHA-256 of the lane’s manifest: its items, their states and reasons, and the hashes of its evidence. A person issues it when they close the lane. A signature ties it to the reviewer’s key; a timestamp from an independent authority shows it existed at that time.
| Lane | Signed by | Time |
|---|---|---|
Information gatheringapi.client.testReceipted | Demo Reviewer Signed with a key | Issued 2026-10-09 11:19:20 UTC Timestamped 2026-10-09 11:19:20 UTC by timestamp.digicert.com |
Manifest SHA-256 dc0b0155df6a04c04916c90b4c5f359046c9ea61d9f0af559d320229d3b5529bEd25519 key 04d6131b52b091033f201537c88e7b13d66abde16d6380f3f8ccb311deac662c | ||
Information gatheringapp.client.testReceipted | Demo Reviewer Signed with a key | Issued 2026-10-09 11:19:20 UTC Timestamped 2026-10-09 11:19:20 UTC by timestamp.digicert.com |
Manifest SHA-256 51c1ec010b939c85aceefab3e30778b10852fded92492b5b089038231fa8a841Ed25519 key 04d6131b52b091033f201537c88e7b13d66abde16d6380f3f8ccb311deac662c | ||
Configurationapp.client.testReceipted | Demo Reviewer Signed with a key | Issued 2026-10-09 11:19:21 UTC Timestamped 2026-10-09 11:19:21 UTC by timestamp.digicert.com |
Manifest SHA-256 6c6025a25ba6ec2d9e9fc4853141c4f4a1857df7bfb1d6d394a0408726a58cb1Ed25519 key 04d6131b52b091033f201537c88e7b13d66abde16d6380f3f8ccb311deac662c | ||
Authorizationapp.client.testReceipted | Demo Reviewer Signed with a key | Issued 2026-10-09 11:30:11 UTC Timestamped 2026-10-09 11:30:11 UTC by timestamp.digicert.com |
Manifest SHA-256 8ed282dde205101815ab8ba63a2e41d07fda63838736c1e37a869c9acc27840aEd25519 key 82e8572262343d35f1a491e5ce139a4bc133d027bdd0a3c95121b4542d8bf337 | ||
Session managementapp.client.testReceipted | Demo Reviewer Signed with a key | Issued 2026-10-09 11:19:21 UTC Timestamped 2026-10-09 11:19:21 UTC by timestamp.digicert.com |
Manifest SHA-256 f37aa01e3b039ec06945c3393eccea320fed9a04e3d7d7b89205e60d107f49fbEd25519 key 04d6131b52b091033f201537c88e7b13d66abde16d6380f3f8ccb311deac662c | ||
1 opened lane has no receipt yet.
How to verify
Anyone can check this report without AttackLedger, the tester’s server or a network connection. The verifier is one
file, tools/verify_report.py in the AttackLedger repository, and needs only Python 3 and its standard library.
1. Get the files
Save this report as JSON (or keep this HTML file: it embeds the same report). Copy verify_report.py and the
tools/tsa-roots/ folder from the repository into one folder, keeping the folder name tsa-roots.
2. Run the verifier
python3 verify_report.py report.json --tsa-root <root.pem>
For example, with the DigiCert root from the repository, or with this HTML file:
python3 verify_report.py report.json --tsa-root tsa-roots/digicert-trusted-root-g4.pem python3 verify_report.py report.html
Roots in tsa-roots/ next to the script are trusted without --tsa-root; pass it for
any other authority. Running python3 -I keeps Python from loading modules from the current folder.
3. Read the result
Each check prints PASS or FAIL; the last line says Verified. and the exit code
is 0 only if every check passed. NOTE lines are information, such as who signed and which receipts are not
timestamped.
| Check | What it means |
|---|---|
| Report body hash | The report has not been edited since it was generated: its SHA-256 matches the recorded value. |
| Evidence chain | Every evidence entry links to the one before it, from the genesis value to the chain head. No entry was removed, reordered or changed. |
| Lane receipts | For every receipted lane, a manifest rebuilt from the report’s own items and evidence has the receipt’s hash, every item marked done has evidence, and every not-applicable item has a reason. |
| Receipt signatures | Each signed receipt verifies with the public key in the report, the key matches its fingerprint, and the signed text names this lane, this manifest and a chain head in the report. |
| Receipt timestamps | Each timestamp token covers this receipt’s manifest hash and signature, the authority’s signature verifies, and its certificate chain reaches a root you trust. Shown only when the report has timestamps. |
Where the timestamp root comes from
tools/tsa-roots/digicert-trusted-root-g4.pem is DigiCert Trusted Root G4, the root of DigiCert’s public timestamp service
(timestamp.digicert.com), taken from the macOS root store and matched against DigiCert’s download. Before you
rely on it, compare its SHA-256 fingerprint with your operating system’s root store or DigiCert’s site:
552F7BDCF1A7AF9E6CE672017F4F12ABF77240C78E761AC203D1D9D20AC89988
Tie keys to people
A valid signature proves the holder of that key signed. To tie the key to a person, ask each signer for their key fingerprint through a channel you trust and compare it with the one in Receipts. To make sure this is the report you were sent, compare the report body SHA-256 on the cover with the value the tester gave you.
Control evidence
Indicative mapping of tests to controls; not a compliance determination.
| Control | Framework | Receipted items | Status |
|---|---|---|---|
| DORA-ART8 Identification of ICT assets and risks | EU DORA (Regulation 2022/2554) | 20/20 | Evidenced |
| ISO-A.5.15 Access control | ISO/IEC 27001:2022 Annex A | 4/18 | Partial |
| ISO-A.5.9 Inventory of information and other associated assets | ISO/IEC 27001:2022 Annex A | 20/20 | Evidenced |
| ISO-A.8.24 Use of cryptography | ISO/IEC 27001:2022 Annex A | 1/12 | Partial |
| ISO-A.8.28 Secure coding | ISO/IEC 27001:2022 Annex A | 0/88 | None |
| ISO-A.8.5 Secure authentication | ISO/IEC 27001:2022 Annex A | 9/38 | Partial |
| ISO-A.8.9 Configuration management | ISO/IEC 27001:2022 Annex A | 11/22 | Partial |
| PCI-11.4.1 A penetration testing methodology is defined and followed | PCI DSS v4.0 | 20/20 | Evidenced |
| PCI-11.4.3 External penetration testing is performed | PCI DSS v4.0 | 24/174 | Partial |
| PCI-6.2.4 Software engineering techniques prevent or mitigate common software attacks | PCI DSS v4.0 | 13/130 | Partial |
| PCI-6.4.1 Public-facing web applications are protected against attacks | PCI DSS v4.0 | 0/64 | None |
Item detail
api.client.test · Information gathering Receipted
| Item | Result | Evidence |
|---|---|---|
| WSTG-INFO-01 Search engine discovery and reconnaissance for information leakage | Evidence recorded | #9 note: lane 6 item 1 checked 59b7af71ae7a |
| WSTG-INFO-02 Fingerprint the web server | Evidence recorded | #10 note: lane 6 item 2 checked 9c26848dc0ee |
| WSTG-INFO-03 Review webserver metafiles for information leakage | Evidence recorded | #11 note: lane 6 item 3 checked 2f0e874c2c66 |
| WSTG-INFO-04 Enumerate applications on the webserver | Evidence recorded | #12 note: lane 6 item 4 checked 2e384a0b0eac |
| WSTG-INFO-05 Review webpage content for information leakage | Not applicable: not present on this host | none |
| WSTG-INFO-06 Identify application entry points | Evidence recorded | #13 note: lane 6 item 6 checked ad5f9a46d6a5 |
| WSTG-INFO-07 Map execution paths through the application | Evidence recorded | #14 note: lane 6 item 7 checked 06f031d963fe |
| WSTG-INFO-08 Fingerprint the web application framework | Evidence recorded | #15 note: lane 6 item 8 checked 70f851c804a2 |
| WSTG-INFO-09 Fingerprint the web application | Evidence recorded | #16 note: lane 6 item 9 checked 8f9a5b303d75 |
| WSTG-INFO-10 Map the application architecture | Not applicable: not present on this host | none |
app.client.test · Information gathering Receipted
| Item | Result | Evidence |
|---|---|---|
| WSTG-INFO-01 Search engine discovery and reconnaissance for information leakage | Evidence recorded | #1 note: lane 5 item 1 checked 21ee57a2d39c |
| WSTG-INFO-02 Fingerprint the web server | Evidence recorded | #2 note: lane 5 item 2 checked 656b53fe693d |
| WSTG-INFO-03 Review webserver metafiles for information leakage | Evidence recorded | #3 note: lane 5 item 3 checked 5f537acc6d23 |
| WSTG-INFO-04 Enumerate applications on the webserver | Evidence recorded | #4 note: lane 5 item 4 checked e28a7f45efb5 |
| WSTG-INFO-05 Review webpage content for information leakage | Not applicable: not present on this host | none |
| WSTG-INFO-06 Identify application entry points | Evidence recorded | #5 note: lane 5 item 6 checked a8372bfca0b7 |
| WSTG-INFO-07 Map execution paths through the application | Evidence recorded | #6 note: lane 5 item 7 checked 39ed9e992992 |
| WSTG-INFO-08 Fingerprint the web application framework | Evidence recorded | #7 note: lane 5 item 8 checked 5fef2da8e444 |
| WSTG-INFO-09 Fingerprint the web application | Evidence recorded | #8 note: lane 5 item 9 checked 906fec458c8e |
| WSTG-INFO-10 Map the application architecture | Not applicable: not present on this host | none |
app.client.test · Configuration Receipted
| Item | Result | Evidence |
|---|---|---|
| WSTG-CONF-01 Test network infrastructure configuration | Evidence recorded | #17 note: lane 7 item 1 checked c4f4624fbd55 |
| WSTG-CONF-02 Test application platform configuration | Evidence recorded | #18 note: lane 7 item 2 checked ddc59ebc9fbb |
| WSTG-CONF-03 Test file extension handling for sensitive information | Evidence recorded | #19 note: lane 7 item 3 checked dcd50c54a3b6 |
| WSTG-CONF-04 Review old backup and unreferenced files | Evidence recorded | #20 note: lane 7 item 4 checked f0714d00399c |
| WSTG-CONF-05 Enumerate infrastructure and application admin interfaces | Not applicable: not present on this host | none |
| WSTG-CONF-06 Test HTTP methods | Evidence recorded | #21 note: lane 7 item 6 checked a20e6deae2ce |
| WSTG-CONF-07 Test HTTP Strict Transport Security | Evidence recorded | #22 note: lane 7 item 7 checked 741b9f30ce73 |
| WSTG-CONF-08 Test RIA cross-domain policy | Evidence recorded | #23 note: lane 7 item 8 checked 4a560040dc2f |
| WSTG-CONF-09 Test file permissions | Evidence recorded | #24 note: lane 7 item 9 checked fdbb9ccc1d79 |
| WSTG-CONF-10 Test for subdomain takeover | Not applicable: not present on this host | none |
| WSTG-CONF-11 Test cloud storage | Evidence recorded | #25 note: lane 7 item 11 checked c433371a14b5 |
app.client.test · Authorization Receipted
| Item | Result | Evidence |
|---|---|---|
| WSTG-ATHZ-01 Test for directory traversal and file inclusion | Evidence recorded | #26 note: lane 8 item 1 checked 7eafbd2fb67f |
| WSTG-ATHZ-02 Test for bypass of the authorization schema | Evidence recorded | #27 note: lane 8 item 2 checked 0853f816af5e |
| WSTG-ATHZ-03 Test for privilege escalation | Evidence recorded | #28 note: lane 8 item 3 checked d99f6940c239 |
| WSTG-ATHZ-04 Test for insecure direct object references | Evidence recorded | #29 note: lane 8 item 4 checked 35faa3133235 |
app.client.test · Session management Receipted
| Item | Result | Evidence |
|---|---|---|
| WSTG-SESS-01 Test the session management schema | Evidence recorded | #30 note: lane 9 item 1 checked 5475b2ca0eac |
| WSTG-SESS-02 Test cookie attributes | Evidence recorded | #31 note: lane 9 item 2 checked 4b042c7c6a62 |
| WSTG-SESS-03 Test for session fixation | Evidence recorded | #32 note: lane 9 item 3 checked 3a15f3647e1e |
| WSTG-SESS-04 Test for exposed session variables | Evidence recorded | #33 note: lane 9 item 4 checked 5e02a08e362f |
| WSTG-SESS-05 Test for cross-site request forgery | Not applicable: not present on this host | none |
| WSTG-SESS-06 Test logout functionality | Evidence recorded | #34 note: lane 9 item 6 checked f99f1db8c936 |
| WSTG-SESS-07 Test session timeout | Evidence recorded | #35 note: lane 9 item 7 checked 4462deeead30 |
| WSTG-SESS-08 Test for session puzzling | Evidence recorded | #36 note: lane 9 item 8 checked 7c90a7bd41f7 |
| WSTG-SESS-09 Test for session hijacking | Evidence recorded | #37 note: lane 9 item 9 checked 0329386ab3ee |
app.client.test · Authentication In progress
| Item | Result | Evidence |
|---|---|---|
| WSTG-ATHN-01 Test that credentials travel over an encrypted channel | Evidence recorded | #38 note: lane 10 item 1 checked caaca830b4a8 |
| WSTG-ATHN-02 Test for default credentials | Evidence recorded | #39 note: lane 10 item 2 checked 3c0208c82e58 |
| WSTG-ATHN-03 Test for weak lockout mechanisms | Evidence recorded | #40 note: lane 10 item 3 checked f15b0d1e8d03 |
| WSTG-ATHN-04 Test for bypass of the authentication schema | Evidence recorded | #41 note: lane 10 item 4 checked ff30bab11c44 |
| WSTG-ATHN-05 Test for vulnerable remember-password functions | Not applicable: not present on this host | none |
| WSTG-ATHN-06 Test for browser cache weaknesses | Evidence recorded | #42 note: lane 10 item 6 checked c3ebef1242f8 |
| WSTG-ATHN-07 Test for weak password policy | Evidence recorded | #43 note: lane 10 item 7 checked 257430959699 |
| WSTG-ATHN-08 Test for weak security question and answer | Open | none |
| WSTG-ATHN-09 Test for weak password change or reset functions | Open | none |
| WSTG-ATHN-10 Test for weaker authentication in alternative channels | Open | none |
Integrity
Every evidence entry commits to the hash of the entry before it, starting from the genesis value, so removing, reordering or editing any entry changes the chain head. The body hash covers everything in the report except this section. The full report is embedded in this page as JSON; see How to verify.