Web Application and API Penetration Testing for a Code Security Platform Provider

Web Application and API Penetration Testing for a Code Security Platform Provider

Industry
Information Technology

Summary

A US-based SaaS provider of a code security platform was preparing for a SOC 2 audit and wanted an independent penetration testing team to thoroughly check the security of its website, seven web applications, and one API. On a tight 7-day deadline, INNERLUXES performed black-box and gray-box testing per the OWASP Web Security Testing Guide, finding only a few non-critical issues and delivering clear corrective measures that strengthened the Customer's compliance evidence.

About the Customer

The Customer is a US-based SaaS provider offering a solution to many cybersecurity challenges in software development. It has created a user-friendly code security platform with vast functionality, including AppSec training, cutting-edge SAST, container analysis, and more. The platform helps developers apply secure coding best practices, detect and remediate code security issues early, and avoid technical debt — ultimately helping develop secure software and save time and money on fixing security issues later in the SDLC.

The Challenge

The Customer maintains SOC 2 certification to guarantee the security of its clients' data and strictly follows the framework's requirements. As part of the preparation for an upcoming SOC 2 audit, the Customer wanted an independent penetration testing team to thoroughly check the security of its website, seven web applications, and one API.

Not fully satisfied with its previous pentesting provider, the Customer was considering other candidates. The key selection criteria were high-quality reports with comprehensive vulnerability descriptions and clearly outlined corrective measures, as well as experience with SOC 2 compliance.

The Solution

Having reviewed INNERLUXES's service proposal and sample reports, the Customer entrusted its pentesting project to the INNERLUXES team. To meet the 7-day deadline, INNERLUXES assigned two experienced pentesters who planned and performed the testing activities in line with the OWASP Web Security Testing Guide.

At the Customer's request, the team started with black-box testing — simulating the approach of real-world hackers, they scanned the website, web applications, and API for vulnerabilities and tried to exploit the detected flaws. The Customer also wanted to explore the security of one web application and its API in more detail, so after black-box pentesting the team received user and admin credentials to test those two targets according to the gray-box approach.

The team was pleased to report that the Customer's efforts to secure its website, web applications, and API had paid off — the testers discovered only a few non-critical issues, in particular:

  • Expiring SSL certificates. If not renewed in time, a malicious actor could launch a man-in-the-middle attack; visitors would also see a warning about an insecure connection, causing reputational damage.
  • Misconfigured Content Security Policy (CSP) that allowed injection of malicious inline scripts and plugins — exploitable to steal data, deface sites, spread malware, and more.
  • Missing security headers that would offer additional protection against clickjacking, content sniffing, cross-site scripting, and other attacks.

None of the detected vulnerabilities posed a serious risk, as it was unlikely an attacker could successfully exploit them. Still, to ensure those minor flaws couldn't facilitate a breach, INNERLUXES recommended fixing them at the earliest convenience and described the corrective measures: purchasing or generating new SSL certificates, adjusting the Content Security Policy, and adding the missing security headers (X-Content-Type-Options, X-Frame-Options, HTTP Strict-Transport-Security, and more).

The Results

  • Having eliminated the issues revealed by INNERLUXES's pentesters, the Customer ensured full security of its website, web applications, and API before the SOC 2 compliance audit.
  • The final report became a valuable addition to the Customer's compliance documentation.

Technologies and Tools

Metasploit, Wireshark, Nessus, Burp Suite, Acunetix, Nmap, DirB.