IT Security · PENTEST

Application Penetration Testing

Remote Admin Security Team·January 27, 2016·4 min read

Application Penetration Testing – security hasn’t been talked about this loudly in a long time. Right now, more and more companies are experiencing stumbles that lead to a loss of trust in the brand they’ve spent years building. Both the companies and their customers lose out here – because stolen data is usually customer data.

It’s currently January, and the market has already seen plenty of company mishaps – one example being the leak of data belonging to two million customers of a company operating in the lending sector.
The leaked data included full personal details such as first name, last name, national ID number (PESEL), and address – data that can be effectively used to fraudulently take out loans online.

Last year, in 2015, cybercriminals obtained a database of 13 million passwords along with email addresses from a hosting service. What can you do with a data set like that? Check whether a user reuses the same password on another site, where their account could then be taken over as well. You could also try to gain access to the user’s mailbox and steal other confidential information.
Who loses out here? Mainly the customer.

The two incidents mentioned above are just a couple of examples – there are thousands more, and those are only the ones we know about. Some companies don’t disclose break-ins at all, meaning customers can’t even react, which is even worse.

You can’t avoid security flaws simply by hiring good developers. To raise the security level of your online store, website, or web application, you need to carry out security testing of your services.

Application penetration testing involves testers taking on the role of hackers who try to find vulnerabilities in the service or product they’ve been given to examine. Such a team is made up of several specialists, usually between 2 and 10 people, who have years of experience breaking through security measures, programming, and system administration alike.

Clients typically ask us to carry out application penetration tests using the so-called black-box model – where our team has minimal knowledge of the system being tested. We therefore act like a typical hacker trying to break into specific resources. We can carry out any task except one – we may not actually damage the system we’re testing.

We also work differently at times: we often receive only the application’s source code from our clients, and based on that we have to determine whether the code contains security flaws or any programmed backdoors, and so on. Here there’s no risk of damaging the system – only time, which can run into hundreds of hours spent analyzing source code for security issues.

Since the security industry doesn’t like to brag – none of you post on social media about which alarm system you installed at home for security reasons, or name the company that installed it – we likewise don’t publish client names in the case studies describing some of the work we’ve carried out, nor do we publicly showcase testimonials from such engagements. We don’t want to put our clients at risk that way.

During one of our most recent engagements, we carried out Application Penetration Testing on an e-commerce solution built on the WordPress platform for one of our clients. With their consent, we publicly disclosed 2 security vulnerabilities we discovered, so that others could protect themselves.
The first vulnerability discovered by our pentesters was a so-called XSS vulnerability found in the Simple Shop plugin for WordPress, which could lead to the takeover of an administrator’s or customer’s account on the e-commerce platform.

The next vulnerability was more critical – an SQL Injection in the eShop plugin for WordPress would have allowed a hacker to gain full access to the web application’s database – in this case, an online store – as well as access to the site’s files, a server shell, and more. Had this vulnerability been found by an actual hacker, it could have led to a full compromise of the site and the company.

Thanks to our work carrying out Application Penetration Testing, our client’s e-commerce platform was secured – and it likely would have only been a matter of time before cybercriminals discovered the vulnerabilities we identified, which would have affected both our client and their customers.

We want to congratulate the client on their responsibility, their commitment to security, and their professional approach, which made it possible to prevent a disaster through a modest investment, rather than later exposing the company to enormous costs to fix things after a security incident – with no guarantee of ever rebuilding customer trust.

We’d like to invite our loyal readers to take part in our promotion, where you can have Application Penetration Testing carried out on your own systems.
Remember that Application Penetration Testing (security) is a process that should be ongoing.
Application Penetration Testing is extremely important, and we hope that with our offer, you’ll be able to raise the security level of your services.