Network Vulnerability Assessment for a US Mobile Credit Services Provider
Summary
A US provider of mobile credit monitoring and reporting services was preparing for PCI DSS validation and needed to detect and prioritize security issues across the systems handling cardholder data before the assessment. INNERLUXES performed a vulnerability assessment of the Client's internal subnetworks and wireless SSIDs, combining reconnaissance, port and application analysis, automated scanning, and manual false-positive reduction. The work surfaced over 300 issues — including several critical ones — and gave the Client a clear remediation path toward PCI DSS compliance.
About the Client
The Client delivers mobile services that give users instant access to their credit reports and scores, alerts on changes to their credit profiles, analysis of credit actions, and daily tracking of results.
The Challenge
As the Client was processing and storing credit card holders' sensitive information, it was getting ready to pass PCI DSS validation, required for all entities dealing with cardholder data. To become PCI DSS compliant, the Client requested INNERLUXES's experts to perform a vulnerability assessment to detect security issues and risks across the related systems and to prioritize and execute remediating actions before validation.
The Solution
INNERLUXES performed a vulnerability assessment of the Client's internal subnetworks and wireless Service Set Identifiers (SSIDs). The assessment consisted of the following phases:
Reconnaissance and host identification
The first phase focused on identifying the Client's hosts through reconnaissance methods such as web searches, Internet Assigned Numbers Authority (IANA) queries, Domain Name System (DNS) crawling, and website inspection for leaked host information. Live hosts were identified through a variety of methods, including standard Internet Control Message Protocol (ICMP) echo requests, Address Resolution Protocol (ARP) requests, ICMP timestamp requests, Transmission Control Protocol (TCP) SYN and TCP ACK packets, and raw IP packets.
Port and application analysis
The target subnetworks were scanned to enumerate open and listening ports and fingerprint running services and operating systems. This was accomplished by sending requests to the host and analyzing its responses.
Vulnerability assessment
Automated vulnerability scanning was performed against the target subnetworks using industry-standard vulnerability assessment tools. Only safe tests were carried out — those that would not crash a system or service.
False-positive reduction
The vulnerability assessment results were correlated with versioning and fingerprinting information to better inspect running services. Additionally, INNERLUXES's experts carried out manual verification of the scanner results using dedicated inspection tools to remove false positives.
Detected vulnerabilities
Although the Client's subnetworks showed a high overall security level, INNERLUXES's team discovered a number of vulnerabilities that could potentially lead to the compromise and disclosure of sensitive information, causing financial losses or affecting the Client's business reputation. Among them were:
- An unsupported version of Microsoft Windows Server. The lack of support meant no new security patches were being released for the product by the vendor, so the Client's network contained a range of security vulnerabilities.
- The Remote Desktop Protocol server (terminal server) was vulnerable to a man-in-the-middle (MitM) attack that could allow an attacker to obtain sensitive information, including authentication credentials.
- A null-session vulnerability. One of the Client's hosts could allow an attacker to log into it using a null session (i.e., with no login or password). Depending on the configuration, an unauthenticated, remote attacker might be able to leverage this to obtain information about the remote host.
- Several web interfaces were exposed to cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
The Results
- Overall, the Client's network showed a high protection level.
- However, the vulnerability assessment revealed over 300 security issues of varying severity, including critical ones that could lead to compromising the Client's network and disclosing sensitive data.
- The assessment allowed the Client to fix the identified vulnerabilities and get ready for PCI DSS validation.
Technologies and Tools
Nessus, OpenVAS, nmap, arp-scan.