Network Pentesting for an MSP to Prevent Man-in-the-Middle and DoS Attacks
Summary
A managed services provider (MSP) experienced in IT support, network security, and disaster recovery wanted an independent, unbiased evaluation of the cyber protection of its external and internal networks. INNERLUXES performed black- and gray-box network penetration testing across 56 IP addresses in under two weeks, revealing several security issues and providing remediation that lifted the networks to a high security level — confirmed during a retest.
About the Customer
The Customer is a managed services provider (MSP) with extensive experience in IT support, network security, and disaster recovery.
The Challenge
Having hands-on experience in cybersecurity, the Customer knows the value of independent audits in ensuring the security of IT assets and sensitive data. The company was looking for an experienced vendor to evaluate the cyber protection of its external and internal networks, and turned to INNERLUXES for an unbiased security evaluation.
The Solution
INNERLUXES examined the perimeter of the Customer's network using the black-box approach: the experts simulated the actions of an attacker with no prior knowledge of the target. As a result, they detected two medium-severity vulnerabilities across the 12 publicly accessible IP addresses. A hacker could exploit these in a man-in-the-middle attack to capture sensitive data exchanged between client and server.
The next stage was gray-box pentesting of the Customer's intranet (44 IP addresses) under low-privilege user credentials. This revealed one high-severity, one medium-severity, and three low-severity issues, including broken access control to SMB shares and outdated software. The vulnerabilities could allow an intruder to obtain sensitive information, modify data, or cause a denial of service.
To fix the issues revealed during the tests, the experts recommended the following remediation actions:
- Removing admin credentials, private keys for certificates, customer information, and other sensitive data from the SMB shared resources.
- Implementing role-based access control to prevent low-privilege users from accessing the backup and storage shares.
- Updating obsolete and vulnerable software components to their latest versions to eliminate over 20 known vulnerabilities found across four hosts.
- Replacing the deprecated and vulnerable TLS 1.0 and lower protocols with TLS 1.2 or TLS 1.3.
- Blocking internet access to services that use unsecured ports and configuring access to local resources via VPN, proxy, or jump host.
During the project, INNERLUXES performed network pentesting following the OWASP Web Security Testing Guide and NIST 800-115, and assessed and classified the vulnerabilities according to OWASP Top 10 and NIST CVSS.
The Results
- INNERLUXES completed black- and gray-box pentesting of the Customer's public and private networks (56 IPs in total) in less than two weeks.
- The remediation recommendations helped the company ensure a high security level for its networks, which was confirmed during a retest round.
Technologies and Tools
Acunetix, cURL, ike-scan, Metasploit, Wireshark, Nessus, Burp Suite, Nmap, DirB, CrackMapExec, smbclient, Telnet, SSLScan, TLSSLed, Python, C, Perl.