Network Penetration Testing for a US Insurance Service Provider
Summary
A US property and casualty insurance company wanted to verify the protection of its networks across two locations and safeguard proprietary data and clients' personal information. In an 11-day remote engagement, INNERLUXES ran two black-box penetration tests, confirmed the networks were well protected, and delivered a final report detailing several security weaknesses and the corrective measures to address them.
About the Client
The Client is a US-based property and casualty (P&C) insurance company. It provides its services to homeowners, small businesses, leading retailers, mortgage lenders, and more.
The Challenge
The Client was interested in checking the protection of its networks situated in two locations. It needed penetration testing services to ensure the security of proprietary data and its clients' personal information stored within these networks.
The Solution
Over an 11-day project, INNERLUXES's security engineers conducted two penetration tests following the black-box approach, carrying out all activities remotely.
The penetration tests led the engineers to conclude that the Client's networks were well protected. However, the team detected several security weaknesses that could result in data breaches if exploited, including:
- The use of outdated SSL/TLS protocols in both networks. Transferring data using these protocols was not safe, as attackers could compromise it.
- The configuration of certain servers allowed disclosing their IP addresses to unauthenticated users. This could let potential attackers obtain the servers' internal IP addresses and further exploit other vulnerabilities in the networks.
- Internet Key Exchange version 1 (IKEv1) aggressive mode was enabled. This misconfiguration could allow cybercriminals to crack the pre-shared key of a VPN gateway and gain unauthorized access to the networks.
- Unauthorized users could send requests with a malicious payload to the servers and reveal details about the directory structure. Unauthenticated users could use this internal information to learn about other weaknesses in the networks.
Having completed the testing activities, INNERLUXES compiled a final report with a list of corrective measures to improve the security level of the Client's networks — recommending changes to server configuration, the use of only updated encryption protocols, disabling directory listing, and more.
The Results
- The Client got expert testing of the protection level of its networks.
- INNERLUXES provided detailed recommendations aimed at reducing the probability of cybercriminals finding attack vectors and accessing the Client's sensitive data.
Technologies and Tools
Metasploit, Wireshark, OpenVAS, Nessus, Burp Suite, w3af, Nmap, sqlmap, DIRB, ZMap.