Gray Box Pentesting for a Risk Management Provider
Summary
A global risk-management provider is dedicated to protecting its platform against emerging cyber threats and regularly engages INNERLUXES for security testing. As part of a long-term cybersecurity partnership, the Customer requested gray-box penetration testing to verify the security of the web, iOS, and Android apps for its travel risk management solution. INNERLUXES completed the pentest and retest in just two weeks, confirming a high security level.
About the Customer
The Customer is a global risk management provider with extensive experience, offering security services including cyber risk management.
The Challenge
Having first-hand experience in security services, including cyber risk management, the Customer is dedicated to protecting its platform against emerging cyber threats. The company regularly engages INNERLUXES to conduct security testing of its IT infrastructure and software components. As part of a long-term cybersecurity partnership, the Customer requested gray-box pentesting to verify the security of the web, iOS, and Android apps for its travel risk management solution.
The Solution
The Customer provided INNERLUXES with user and administrator credentials for the target applications. The pentesters started with a vulnerability assessment: they scanned the apps using automated tools and manually validated the results. Next, the team imitated the actions of a real-life attacker with partial access to the targets, attempting to exploit the found vulnerabilities to evaluate their potential impact. The penetration testing activities were based on the best practices outlined by PTES, the OWASP Web Security Testing Guide, the OWASP Mobile Security Testing Guide, and NIST 800-115.
Finally, the team analyzed the findings, classified the discovered issues according to OWASP Top 10 and OWASP Mobile Top 10 standards, and reported the results. The pentesting confirmed the high security level of the web and mobile applications and revealed only a few non-critical weaknesses.
INNERLUXES suggested measures to further enhance the apps' security, including:
- Using HTTP headers, such as X-Frame-Options and Content Security Policy, to enhance web application protection against clickjacking, cross-site scripting, and other common attacks.
- Updating obsolete software to its latest version.
- Updating the password policy to require stronger passwords.
- Implementing brute-force protection (e.g., adding CAPTCHA, limiting failed login attempts).
After the Customer applied the fixes, INNERLUXES retested the apps and validated the successful remediation. The team completed the project — pentesting and retest — in just two weeks.
The Results
- The gray-box penetration testing confirmed the efficiency of the Customer's security controls and provided insights for further security enhancements.
- Thanks to prior knowledge of the Customer's IT ecosystem and an optimal blend of manual and automated testing, INNERLUXES performed a comprehensive pentest in just two weeks.
- The detailed recommendations allowed the Customer to quickly remediate the non-critical vulnerabilities and gain full confidence in the cyber resilience of its web, iOS, and Android applications.
Technologies and Tools
Metasploit, Nessus, Burp Suite, Acunetix, Nmap, SSLScan, WhatWeb, Nikto, DirB, MobSF, Wireshark, Radare2, Ghidra, Apktool, Jadx, Hopper, Frida, Objection.
Custom scripts in Python, C, and Perl.