Black Box Penetration Testing of the Payment IT Infrastructure
Summary
A North American provider of payment services and products for financial institutions and small businesses handles clients' personal and financial data that could be a prime target for intruders. To evaluate the security of its webservers and web applications, the company engaged INNERLUXES for black-box penetration testing. Within a strict 7-day limit, INNERLUXES assessed the website and webserver per the OWASP Top 10, revealed the most critical vulnerabilities, and provided risk-mitigation recommendations.
About the Client
The Client is a North American provider of services and products for financial institutions and small businesses, serving millions of small businesses and thousands of financial institutions across the United States and Canada.
The Challenge
The Client's service set includes web services for processing and storing clients' personal and financial data that can be of great interest to potential intruders. The Client decided to turn to a penetration testing provider to evaluate the security of its webservers and web applications and to identify vulnerabilities by simulating attackers' actions and unauthorized access to its data and IT resources.
The Solution
Due to the strict time limit the Client assigned to the project (7 days), the company's website and webserver were chosen as the objects for pentesting. The major objective was to reveal whether attackers could reach the Client's sensitive data and whether other network objects could be put in danger if an intruder hacked the website.
INNERLUXES's pentester acted as an offender with access to the Client's network through the Internet only, producing technical attacks without using social engineering. This was black-box testing, with only the company name and the URLs of the web applications provided.
The web penetration testing was based on the OWASP Top 10 methodology, which represents the list of the ten most dangerous security flaws in current web applications along with effective methods for dealing with them.
Major methodological components such as cross-site scripting (XSS), security misconfiguration, sensitive data exposure, and components with known vulnerabilities were applied to detect the potential to:
- Perform man-in-the-middle exploits (those taking advantage of the Internet and security software), including POODLE attacks.
- Hijack user sessions using cross-site scripting (XSS).
- Perform null-byte injections through webserver misconfiguration.
- Inject plaintext into an application protocol stream.
- Carry out collision attacks.
INNERLUXES revealed a range of vulnerabilities of different risk levels that could affect the company's network and cause client data leaks. The Client was therefore provided with a set of recommendations on measures to mitigate the risks and minimize the possibility of intrusion.
The Results
- INNERLUXES performed penetration testing in an extremely short timeframe of just one week.
- Despite the limit, the white-hat hacker completed the assessment of the Client's website and webserver and revealed the most critical vulnerabilities that attackers could potentially exploit.
- Fully satisfied with the services, the Client intends to continue the partnership with INNERLUXES and start a deeper analysis of its IT infrastructure.
Technologies and Tools
Nmap, sqlmap, Metasploit, OpenVAS, w3af, Burp Suite, fierce, manual testing.