IT Infrastructure Pentesting and a Phishing Campaign for a EU Energy Company
Summary
A European energy company running an LNG-to-power plant wanted to thoroughly test its IT infrastructure for vulnerabilities that could compromise the plant's workflows, and to check its resilience to phishing. Lacking in-house cybersecurity experts, it engaged INNERLUXES. Within a 14-day deadline, INNERLUXES performed gray-box penetration testing per the NIST 800-115 methodology and staged an email phishing campaign — uncovering critical vulnerabilities, delivering a prioritized remediation roadmap, and confirming the resilience of the company's email security tools.
About the Client
The Client is a European energy company. It runs an LNG-to-power plant that delivers safe and reliable electricity while reducing carbon emissions in the region.
The Challenge
Aware of the scale and devastating consequences of cyberattacks in the energy sector, the Client wanted to thoroughly test its IT infrastructure for vulnerabilities that could compromise the power plant's workflows. Lacking the necessary cybersecurity experts on board, the Client was looking for an experienced penetration testing vendor. With social engineering attacks being one of the most common threats faced by energy companies, the Client also wanted the chosen vendor to check its resilience to phishing.
The Solution
INNERLUXES took on the project. The targets of penetration testing included the Client's corporate website, 2 web servers, 4 public-facing IPs, 20 internal subnetworks, and 14 Wi-Fi access points. INNERLUXES's team was also to stage social engineering attacks on the Client's employees.
Gray-box penetration testing of IT infrastructure
To thoroughly check the Client's IT infrastructure within the 14-day deadline, INNERLUXES's security testing team chose the gray-box penetration testing approach. For that, they were provided with credentials to log in under low-privileged user roles. The team planned and performed the project according to the NIST 800-115 methodology, with threat classification based on the NIST CVSS score.
The penetration tests showed that the security level of the Client's IT infrastructure was low, as it contained a number of critical security issues:
- Missing or poor authentication for critical functions (access to the database management and network monitoring systems). An intruder only needed to gain low-privileged access to the Client's internal network to be able to manipulate the database or the network monitoring tools.
- Default Perlinfo and PHPinfo pages that could disclose information about the web server (e.g., server OS and environment variables, Perl and PHP configurations). A potential hacker could use this information to plan and execute further attacks.
- Unsupported versions of remote Microsoft and Apache web servers containing multiple known vulnerabilities that could enable CRLF injection, arbitrary code execution, XSS, DoS attacks, and more.
- The corporate website running on an outdated PHP version with known vulnerabilities that could be exploited for SQL injections, cross-site scripting, and other attacks.
- 2 workstations using an unsupported version of Windows OS that contained vulnerabilities enabling a variety of potential attacks, including buffer overflow, directory traversal, and arbitrary code execution.
To help the Client's IT team promptly fix the detected issues and prevent potential security breaches, INNERLUXES's experts provided a detailed description of the vulnerabilities found and the required remediation measures. INNERLUXES recommended:
- Setting up stricter authorization mechanisms that only allow admin users to access critical IT infrastructure components.
- Removing the informational files or restricting access to them.
- Using supported versions of the OS, web servers, and PHP that offer enhanced security and regular updates.
Email phishing campaign
INNERLUXES staged a bulk phishing attack targeting 60 corporate emails belonging to the Client's employees. To simulate a real-life phishing spam scenario and check the efficiency of email protection, the IPs used by the testers were not whitelisted.
INNERLUXES's team was pleased to report that the Client's anti-phishing tools managed to stop the malicious emails. To ensure complete protection against phishing, INNERLUXES recommended evaluating the employees' cybersecurity awareness through interviews and conducting another round of social engineering testing using whitelisted IPs.
The Results
- Within 14 days, the Client received an exhaustive list of vulnerabilities in its IT infrastructure and a remediation roadmap with prioritized corrective measures.
- The phishing campaign gave the Client proof of the efficiency of its email security tools, along with recommendations for boosting employees' security vigilance against other kinds of social engineering attacks.
- Satisfied with INNERLUXES's proactive approach and clear, comprehensive reporting, the Client is willing to contract INNERLUXES's team again for future security checkups.
Technologies and Tools
Metasploit, Wireshark, Nessus, Burp Suite, Acunetix, Nmap, Dirb.