“But we already implemented that.”
This is something we occasionally hear after reporting a vulnerability.
The development team checks the application and confirms:
- The button is hidden.
- The option is disabled.
- The user cannot perform that action through the GUI.
So why is there a vulnerabilty?
Yes — the control may already exist in the GUI.
But can it be bypassed?
And that’s where the difference between QA and penetration testing becomes important.
Your GUI Is Not a Security Boundary
Let’s say a normal user is not allowed to access another user’s account.
The application may prevent this by hiding certain options or restricting what the user can select.
From the GUI, everything looks correct.
But what happens if someone ignores the GUI and sends the request directly to the backend?
If the backend does not independently verify whether the user is authorised to perform that action, the frontend restriction can potentially be bypassed.
Your frontend controls what users can see. Your backend must enforce what they are actually allowed to do.
Attackers Don’t Follow Your User Flow
A legitimate user generally follows the workflow you designed:
Login → Dashboard → Select Account → Perform Action.
An attacker doesn’t have to.
They can intercept requests, modify parameters, change IDs, call APIs directly, skip steps or send requests in an unexpected sequence.
They may not even care what your GUI looks like.
To a developer, this can sometimes seem unusual:
“But a normal user wouldn’t do that.”
Exactly.
A penetration tester isn’t testing a normal user. They’re testing what an attacker could do.
A Penetration Test Is Not Another Round of QA
QA verifies whether the application works as intended.
Penetration testing asks what happens when someone deliberately tries to use the application in ways it was never intended to be used.
That’s why a pentester may:
- Modify request parameters
- Change user or object IDs
- Call APIs directly
- Attempt actions using another user role
- Skip steps in a workflow
- Perform actions in an unexpected sequence
The goal isn’t to prove that the GUI works.
The goal is to find out whether the application’s security controls can be bypassed.
The Key Difference
QA asks:
Does the application work as intended?
Penetration testing asks:
What happens if someone deliberately ignores how the application was intended to be used?
Both are important, but they serve very different purposes.
So when your penetration tester doesn’t follow the documented user flow, that’s not necessarily a problem.
That’s the point.
Your attacker doesn’t follow your user flow.
Neither should your penetration tester.
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Don’t just test what your users can do. Test what an attacker can get away with.
Explore our VAPT & Penetration Testing Services
If you’re a Singapore SME, you may also be eligible for the CSA-supported CISOaaS VAPT Grant, which provides funding support for eligible penetration testing engagements.








