Home/Case studies/B2B applications

Case study · IT Security

Securing the software development lifecycle (SDLC) with the Reconmore scanner

How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.

ReconMoreSoftware House

Client

A software house building custom B2B web applications for business clients. The company’s currency is the trust of its enterprise clients — every vulnerability in released code risks damaging the reputation of those who commission the work.

Challenge

Even the best development teams make mistakes under time pressure. The client needed a final, hard line of defense before code went to production — independent of its own team and running continuously, not once a year.

Scope of work

  • Reconmore continuous vulnerability scanning for production and test environments
  • Infrastructure flaw detection: exposed .git directory (Critical) — a misconfiguration that allowed an attacker to download the application’s entire source code from the server
  • Credentials leak (High): plaintext database credentials discovered
  • Missing encryption (High): communication channels not secured with TLS
  • XSS analysis in the code itself: Reflected Cross-Site Scripting (High) — an improperly encoded parameter whose exploitation could lead to phishing attacks on end customers, session hijacking, or even page content spoofing (an attack on the brand’s image)

How the engagement worked

Scanner deploymentContinuous scanning of production and test environments launched under an initial 3-year contract.
Continuous scanningDuring the first contract, nearly 60 serious flaws were detected, 38 of them classified as critical to the security of released applications.
Reports and consultationsThe client regularly received detailed reports (classification, remediation recommendations, business risk analysis), along with technical meetings with our engineers.
Re-testsFree re-tests after code updates confirmed the fixes were effective — and led to the cooperation being extended for more years.

Results and value for the client

Reconmore became a permanent part of the client’s release cycle — the final checkpoint before production. Catching the open .git directory and the XSS vulnerability protected the reputation of the software house and its clients. The cooperation has continued uninterrupted for 6 years; after the first 3-year contract, the agreement was extended for another 3 years.

We build advanced B2B applications. Our currency is the trust of our enterprise clients. Reconmore has become our final, hard line of defense before code goes to production. Catching the open .git directory and the XSS vulnerability saved our reputation and that of our clients. Extending our contract with Remote Admin for another 3 years was the easiest business decision we have made.

Board Member / Owner, Software House — details under NDA

Other projects

See more case studies

All projects →
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →
IT SecurityCooperative banking

Annual security audit of a Cooperative Bank’s infrastructure and systems

A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.

3 monthstesting cycle
100%fix effectiveness in re-tests
Read the case study →
IT SecurityFinTech · cryptocurrency exchange

Deploying the Reconmore scanner at a cryptocurrency exchange

Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.

17vulnerabilities found in the first month
24 monthsof continuous protection
Read the case study →