Code Review and Pentesting in 7 Days to Prevent Critical Issues Before App Launch

Code Review and Pentesting in 7 Days to Prevent Critical Issues Before App Launch

Industry
Information Technology, Software products

Summary

A European IT company that develops tax and accounting products wanted to ensure a high protection level for its cloud-based tax-returns application before offering it to clients. INNERLUXES had 7 days to perform automated and manual source-code reviews and penetration testing — uncovering critical issues that could expose sensitive cloud data and delivering prioritized corrective measures before the app's market release.

About the Customer

The Customer is a European IT company that develops tax and accounting products. These solutions facilitate tax-return and corporate tax-computation processes and let the Customer's clients file taxes digitally.

The Challenge

The Customer was interested in ensuring a high protection level for its cloud-based application for tax returns before offering it to clients. It turned to INNERLUXES for automated and manual source-code reviews and penetration testing of the product before its release.

The Solution

INNERLUXES's security testing team had 7 days to perform the source-code reviews and penetration testing. The major objective was to reveal whether attackers could access the clients' sensitive data stored in the Customer's cloud.

An automated source-code review was carried out with IBM Application Security on Cloud, while an INNERLUXES solution architect conducted a manual source-code review. The combination of manual and automated checks gave the security engineers an in-depth understanding of the critical issues found in the source code of the cloud application. Exploitation of the identified weaknesses could interrupt the app's operation, affect the security of the data stored in the cloud, and lead to data leakage (users' passwords, for example).

Upon completing the source-code reviews, the team drew up a list of issues with detailed descriptions and recommended corrective measures.

INNERLUXES's security engineers then conducted penetration testing, during which the team detected the cloud application's susceptibility to:

  • Cross-origin resource sharing.
  • Brute-force attacks.
  • Users' password decryption when stored in temporary storage.
  • Phishing attacks.

The team revealed a range of vulnerabilities of different severity levels and defined the following corrective measures:

  • Configuring the domain policy that provides access to the resources of the cloud app and the server.
  • Adding a failed-login-attempts limitation.
  • Using a secret storage that encrypts passwords even when stored in temporary storage.
  • Ensuring the cloud app and server control the links through which users could be redirected to potentially malicious websites.

The Results

  • The Customer received the list of vulnerabilities revealed during the source-code reviews and penetration testing of its cloud tax-returns application.
  • The Customer received direct recommendations and corrective measures to implement, improving the security of its cloud app before placing it on the market.
  • Solving the issues revealed by INNERLUXES ensures a high protection level for the sensitive client data stored in the Customer's cloud.

Technologies and Tools

Metasploit, Wireshark, OpenVAS, Nessus, Burp Suite, w3af.