Network Penetration Testing for a US Law Firm

Network Penetration Testing for a US Law Firm

Industry
Legal Services

Summary

A US law firm that handles large volumes of confidential information — clients' personal and bank information, intellectual property, and more — was concerned that security gaps in its extensive IT network could lead to financial losses and reputational damage. As a step toward solid cyber defense, the firm engaged INNERLUXES to evaluate the corporate network's security level and fix found vulnerabilities to prevent unauthorized access to sensitive data.

About the Customer

The Customer is a US law firm that provides worldwide legal advisory services in real estate, insurance, finance, environment, intellectual property, labor and employment, construction, and other areas.

The Challenge

Dealing with large amounts of confidential information (clients' personal information, bank information, intellectual property, etc.), the Customer was concerned that potential security gaps in its extensive IT network could lead to huge financial losses and reputational damage. As a step toward solid cyber defense, the Customer needed to evaluate the security level of the corporate network and fix found vulnerabilities to prevent unauthorized access to sensitive data.

The Solution

The Customer commissioned INNERLUXES to perform IT network security testing. INNERLUXES's cybersecurity specialists conducted black-box and gray-box penetration testing in 11 days. The black-box approach presupposed strictly limited knowledge of the network, while during gray-box testing the engineers had valid user credentials to operate within the network.

Network penetration testing included:

  • Automated vulnerability scanning of the external perimeter and internal network environment, including servers, employee workstations and network services, firewalls, IPS, etc.
  • Manual validation of automated scanning results.
  • Defining the severity of detected vulnerabilities according to commonly used NIST CVSS standards.
  • Exploiting critical vulnerabilities and attempting to break into the network to access sensitive data via imitation of brute-force attacks, input data manipulation, etc.

The overall network security level was assessed as low due to over 100 found security issues, including:

  • Outdated versions of Cisco TelePresence VCS, OpenSSH, and SSL.
  • Unsupported Windows and UNIX OS versions.
  • Improper processing of packets by the Secure Channel security package.
  • Browsable web directories.
  • Null-session (no login or password) authentication on a remote host.
  • Unsupported version of Microsoft SQL Server, etc.

INNERLUXES documented all issues and offered detailed remediation guidance. In addition to technical recommendations, INNERLUXES recommended social-engineering testing to check the security awareness of the Customer's employees and see whether they need IT security training.

The Results

  • The Customer received detailed reports describing the detected vulnerabilities, their classification by severity and likelihood of exploitation, and recommendations on how to mitigate them.
  • After the vulnerabilities were fixed according to the suggested remediation plan, INNERLUXES carried out re-testing and confirmed an increased security level of the Customer's IT network.

Technologies and Tools

Metasploit, Wireshark, Nessus, Burp Suite, Nmap, w3af, cURL, Nikto, DirB, SSLScan; custom scripts (Python, C, and Perl to exploit vulnerabilities).