All-Around Security Testing for Electromagnetics R&D Company
Summary
An R&D company that innovates electromagnetic and acoustic solutions for military and commercial applications needed comprehensive security testing for its application and large-scale network. In just seven days, INNERLUXES completed vulnerability assessment, black- and gray-box penetration testing of 500 IPs and a web app, and a social-engineering simulation against 50 corporate emails — confirming a high security level and high employee awareness, with only a few non-critical findings.
About the Customer
The Customer is an R&D company with deep experience in innovating electromagnetic and acoustic solutions for military and commercial applications.
The Challenge
The Customer was looking for comprehensive security testing for its application and large-scale network, and turned to INNERLUXES.
The Solution
Black box and gray box penetration testing
INNERLUXES's experts performed penetration testing following PTES, OWASP Web Security Testing Guide, and NIST 800-115 methodology, and classified the discovered issues according to OWASP Top 10 and NIST CVSS standards.
The project started with external testing of the Customer's public app and network of 5 IP addresses. The pentesters performed a vulnerability assessment using a combination of automated scanning and manual approach to ensure wide coverage with zero false positives. During black-box pentesting, they attempted to exploit the found vulnerabilities to evaluate their potential impact, revealing two low-severity issues in the web app:
- Missing HTTP security headers that protect against man-in-the-middle (MitM), clickjacking, cross-site scripting (XSS), and other common attacks.
- Outdated and vulnerable versions of NGINX products, jQuery, Bootstrap, and other software that posed the risk of memory disclosure, untrusted code execution, and XSS.
The next stage was internal pentesting of the Customer's private network of 495 IP addresses. The team followed the gray-box approach to imitate an attacker who gained user access to the targets, revealing 4 low-severity issues:
- Outdated and vulnerable versions of OpenSSH, MySQL, Apache HTTP Server, and other software posing the risk of attacks like denial of service (DoS) and request smuggling.
- Insecure protocol versions TLS 1.0 and TLS 1.1 supported by several remote services that could allow information disclosure.
- Access to the FTP server without credentials that could be used to fetch potentially sensitive data or facilitate a DoS attack.
- Weak cryptography posing the risk of MitM attacks against SSH and TLS connections and subsequent sensitive-data leakage (e.g., session key, session messages, and HTTPS cookies).
The pentesting confirmed the high security level of the Customer's web application and networks and revealed only a few non-critical vulnerabilities. To address them and further enhance cyber defense, INNERLUXES suggested corrective measures, including:
- Configuring the missing security headers, such as Strict-Transport-Security and Content Security Policy.
- Updating obsolete and vulnerable software to its latest version and hiding software versions.
- Implementing brute-force protection (e.g., adding CAPTCHA, limiting failed login attempts).
After the Customer applied the fixes, INNERLUXES retested the app and validated the successful remediation.
Social engineering testing
Based on publicly available information about the company, INNERLUXES's pentesters prepared and ran several phishing scenarios against 50 corporate email addresses. They sent emails with "malicious" URLs (showing if the user followed the link), executable files (showing whether the user downloaded and installed them), and fake invitations and forms. The Customer's employees followed safety precautions and ignored the phishing emails.
The Results
- The black- and gray-box penetration testing of 500 IPs and a web app confirmed the efficiency of the Customer's security controls and provided insights for further security enhancements.
- The social-engineering simulation against 50 emails proved the employees' high cybersecurity awareness.
- Thanks to an optimal blend of manual and automated testing, INNERLUXES completed vulnerability assessment, pentesting, and social-engineering testing in just seven days.
- The detailed recommendations allowed the Customer to quickly remediate the non-critical vulnerabilities and gain full confidence in its application and network cyber resilience.
Technologies and Tools
Nessus, Acunetix, Burp Suite, Nmap, SSLScan, DirB, CrackMapExec, smbclient, SSHscan, ldapsearch, NBTscan, rpcclient, SMBMap, PHP, Bash, Python, PowerShell.