All the best work in the world won't mean anything to the customer unless it is turned into comprehensive, actionable, and insightful guidance. Many technical professions have been ended prematurely or stunted due to an inability to communicate the work. Besides permission and intent, the other thing that separates us from the black-hat hackers is our communication with the customer. We must be teachers and coaches – for many of our customers, this will be a scary and gut-wrenching process, but we need to deliver guidance that they can use to improve.
What about clean-up? Well, web application pen testing is (for the most part) devoid of permanent changes to the environment. In most of the exploits that we have used, a simple cache wipe of the browser or scrub of the fields on the web frontend will return the application to its normal operating state.
...