Web Application and Network Pentesting for an Asset Management Company

Web Application and Network Pentesting for an Asset Management Company

Industry
BFSI, Consulting, Investment, Professional Services, Real Estate

Summary

A US-based asset management company serving real estate lenders and investors worldwide handles large volumes of sensitive client data and is subject to regulations including GDPR and US state privacy laws. As part of its risk mitigation, it adopted regular penetration testing and sought a reliable, long-term security testing partner. INNERLUXES carried out black-box and gray-box pentests of the company's web application and public-facing IPs across multiple yearly engagements — finding no critical flaws and confirming a high security level with retests and attestation letters.

About the Client

The Client is a US-based asset management company. It provides services to real estate lenders and investors across many countries around the globe.

Penetration testing to check sensitive data safety

In the course of its business activities, the Client stores and transmits large amounts of client information, including personal identifiers and financial details. The company is therefore subject to several data security regulations, including GDPR and US state privacy laws.

To protect the sensitive data it handles and stay compliant, the Client implements, evaluates, and upgrades its security policies, processes, and technical controls. It added regular penetration testing to its list of risk mitigation measures and wanted to find a reliable security testing vendor that could become a long-term partner. It performed a thorough review of potential candidates, with the main criteria being vast pentesting experience, a SOC 2 or ISO 27001 certificate, a sound information security policy, and transparent reporting.

Regular pentesting ensured timely vulnerability remediation

INNERLUXES was chosen by the Client for an independent security checkup of its web app and network. Satisfied with INNERLUXES's attention to detail and final reports that helped the in-house IT team smoothly fix the detected security issues, the Client continued the cooperation. In the following engagement, INNERLUXES performed a series of black-box and gray-box pentests to see whether modifications in the web app and network had introduced any new vulnerabilities. With this being a positive experience on both sides, the Client had no hesitation about which vendor to contact for subsequent security testing. When the time for the next regular checkup came, the Client again requested black-box and gray-box penetration testing from INNERLUXES.

To see whether a real-world attacker could infiltrate the Client's IT environment, INNERLUXES's team started with black-box testing of the web application and ten public-facing IPs. After that, they were provided with user credentials and conducted gray-box penetration testing to gain a deeper insight into the web app's security. Combining automated tools with manual techniques, INNERLUXES's ethical hackers checked every possible attack scenario.

As a result, they were pleased to prove that the Client's scrupulous approach to cyber defense and regular security assessments paid off: the testing targets contained no critical security flaws. The testers only found several vulnerabilities of low and informational severity according to the OWASP Top 10 and NIST CVSS classification, such as deprecated TLS 1.1 in use, missing security headers, and lacking brute-force protection. The detected weaknesses were difficult to exploit; in the worst case, intruders could obtain only non-critical information that would not compromise the web app or network.

After completing the testing activities, the team provided detailed reports describing the testing process, findings, and required corrective measures. To further improve the web application's security, INNERLUXES's experts recommended performing security code reviews for each subsequent app version.

Willing to share their cybersecurity knowledge to help achieve the best results, INNERLUXES's pentesters welcomed additional questions from the Client's IT team about the detected vulnerabilities and how to fix them.

After the Client eliminated the detected security issues, INNERLUXES performed retesting, which proved the high security level of the web application and public-facing IPs.

High security level confirmed by attestation letters

  • After pentesting and retesting by INNERLUXES, the Client was fully assured that its web application and public-facing network components contained no security vulnerabilities.
  • The Client also received executive reports and attestation letters to prove its high security level to auditors and clients.

Technologies and Tools

Burp Suite, Acunetix, Nmap, Dirb, Metasploit, Nessus, Nikto.