Web Application Penetration Testing for a European Bank
Summary
A European bank serving private and corporate customers needed to evaluate the security of certain web applications and confirm its customers' sensitive information was properly protected. The apps handle popular banking services — processing and storing data such as payment card numbers, transaction details, and phone numbers. INNERLUXES performed black-box web application penetration testing per the OWASP Top 10, revealed vulnerabilities across four risk categories, and provided a prioritized remediation plan.
About the Client
The Client is a European bank that provides a full spectrum of banking services for private and corporate customers.
The Challenge
The bank sought a penetration testing provider to evaluate the overall security of certain web applications and check whether its customers' sensitive information was properly protected. It turned to INNERLUXES's experts, who had carried out information security, fraud protection, and penetration testing projects for banking institutions. INNERLUXES was asked to test web applications that let the bank's customers use popular banking services — which implied processing and storing personal information (e.g., payment card numbers, transaction details, phone numbers, and more).
The Solution
To carry out high-quality, comprehensive testing, INNERLUXES's penetration testers used the OWASP Top 10 methodology, which identifies the most critical web application security flaws and provides detailed guidance on eliminating detected vulnerabilities. To ensure accurate results, the team used both manual and automated testing tools and techniques.
The pentesters chose the black-box testing model — simulating various cyberattacks with internet access only, repeating a real outside-attack scenario in which an attacker would exploit web app vulnerabilities to reach critical data. During the test, they applied a range of methods to evaluate the apps' resistance to SQL injection, cross-site scripting, and cross-site request forgery, and to detect security misconfigurations, components with known vulnerabilities, unvalidated redirects and forwards, and more. They also performed sophisticated brute-force attacks to check the reliability of authentication security controls.
The testing revealed several vulnerabilities that fell into four categories as defined in the OWASP methodology. To help the Client patch these gaps, INNERLUXES provided a list of feasible measures to restore the required level of security and customer data protection in the shortest possible time.
The Results
- INNERLUXES performed 10 different penetration tests to analyze the security of the Client's web apps.
- The testing revealed 4 types of vulnerabilities classified according to the risk levels defined in the methodology.
- INNERLUXES's experts drew up a detailed remediation plan and recommended that the Client focus on authentication and data validation issues as fundamental to protecting sensitive information.
Technologies and Tools
Methodology: OWASP Top 10.
Tools: Burp Suite, Acunetix, Google Chrome Developer Tools, Python, WPScan, Nessus, Nmap, sqlmap, Metasploit.