Pentesting for a Communications Vendor to Ensure Robust Security and GDPR and ISO 27001 Compliance
Summary
INNERLUXES conducted black-box, white-box, and gray-box penetration testing of the IT network and web apps, plus an email phishing campaign, for a smart communication solutions vendor. As a result, the Client enhanced its IT security posture and ensured its clients' data protection as required by GDPR and ISO 27001.
About the Client
The Client is a smart communication technology vendor that powers businesses with automated solutions for fast and cost-effective communication with customers — smart voicebots, SMS, and global telephony. The Client's products help its customers optimize business processes, achieve higher lead generation and conversion, and increase customer satisfaction.
Aiming to improve its cyber defense and protect its clients' data according to GDPR and ISO 27001, the Client wanted to test its IT network, the web applications supporting its internal processes, and its software products to reveal and eliminate potential security gaps. One of its requirements was that the security testing provider be physically present in the EU during the project, to comply with GDPR.
Penetration Testing of Web Applications and Internal Network
The Client requested comprehensive penetration testing of the applications and internal network, with a special focus on its communication solutions. To get a full view of existing vulnerabilities and explore all possible cyberattack scenarios, INNERLUXES applied all three main approaches — black-, gray-, and white-box pentesting — across three consecutive stages:
1. Black-box testing of the web apps and APIs that support the Client's internal processes. The testers first approached the target web apps and APIs without any prior knowledge of them, closely simulating real-world hackers' actions to detect vulnerabilities that could serve as entry points to break through the external security perimeter.
2. Gray-box testing of the internal network. At this stage, INNERLUXES's security engineers received limited information about the internal network — user credentials and network architecture — and tested 76 IPs, exploring how a potential intruder could compromise the company's sensitive data and IT assets once inside the system.
3. White-box testing of the Client's software products. The testers were provided with admin rights and full information about the communication solutions to detect all possible security issues, exploring the source code of the web apps and APIs and performing targeted tests to define all possible attack vectors.
Upon completing the testing, the Client received a detailed report on the detected security gaps, including:
- Poor or missing authentication mechanisms.
- Access control vulnerability: one user could see or modify another user's information without permission.
- Absent brute-force protection (e.g., a request rate limit or account lockout after a number of failed logins), allowing a potential attacker to obtain user credentials or other sensitive information.
- Outdated software with known vulnerabilities that could enable remote code execution, information disclosure, and denial-of-service attacks.
- Unprotected communication due to using TCP Port 80, which sent unencrypted responses.
The 18 detected vulnerabilities were categorized by severity and likelihood of exploitation, allowing the Client's team to prioritize remediation steps. The Client also received detailed guidance on the necessary corrective measures, such as:
- Enforcing strong authentication mechanisms.
- Implementing a request rate limit and enabling account lockout.
- Reviewing the Universally Unique Identifier (UUID) system and implementing additional authentication checks.
- Updating and patching vulnerable software.
- Using Port 443 instead of Port 80.
Guided by the report and remediation roadmap, the Client's team promptly fixed the discovered vulnerabilities. After INNERLUXES performed a retest, the Client got tangible proof of increased data protection as required by GDPR and ISO 27001.
Email Phishing Campaign
Knowing that human error and negligence can sabotage even the strongest IT security systems, the Client wanted to check whether its employees could resist social engineering attacks. INNERLUXES simulated bulk phishing attacks using emails with malicious links and fake login forms, revealing several cases of careless employee behavior that could lead to a security breach.
As a result, the Client received actionable employee training recommendations that helped it promote cybersecurity awareness among staff and enhance their resilience to phishing attacks.
Key Outcomes
- Increased security of the IT network, the web applications supporting internal processes, and the software products, thanks to comprehensive black-, gray-, and white-box pentesting and actionable remediation guidance.
- Enhanced cybersecurity awareness of the staff as a result of social engineering testing and follow-up employee training recommendations.
- Ensured protection of clients' data as required by GDPR and ISO 27001.
- A solid reputation as a secure communication solutions vendor and increased customer trust.