Web Application Penetration Testing for a Professional Conference Organizer
Summary
A US-based organization that arranges international conferences for applied-sciences researchers needed to evaluate the security of a new web application for managing conference planning and coordination — from attendee registration to travel and accommodation. Before launch, and on a two-week deadline, INNERLUXES performed gray-box penetration testing of the app and its APIs, finding no exploitable vulnerabilities and providing actionable security-management recommendations.
About the Customer
The Customer is a US-based organization that arranges international conferences for researchers in applied sciences such as medical sciences and engineering, holding a large number of events annually.
The Challenge
The Customer needed to evaluate the security of its new web application, which would help manage conference planning and coordination — from registering attendees to arranging travel and accommodation. Before launching the app, they wanted to ensure it contained no security flaws that could compromise the Customer's or the conference participants' data. The Customer sought a reliable security testing vendor with proven technical expertise, the ability to conduct penetration testing on short notice (within only two weeks), a clear reporting format, and actionable recommendations for fortifying the app's security.
The Solution
Given the time constraints, INNERLUXES's security team chose the gray-box approach, which allowed thorough exploration of the web application and its 5 APIs within a short period. The security engineers were provided with credentials to test under different user roles — Headquarters Staff, Venue Staff User, Organizer, and Conferee — and planned and performed the penetration testing according to the OWASP Web Security Testing Guide methodology.
Having exhausted all possible ways to break through the application's security, INNERLUXES's testers were pleased to report that there were no vulnerabilities a potential attacker could exploit. To help maintain such a high level of cyber defense and prevent future data breaches, INNERLUXES recommended establishing consistent security-management policies, such as:
- Performing continuous check-ups for known vulnerabilities — ideally running vulnerability scanners once a week.
- Documenting all changes to the web app and conducting vulnerability assessment and penetration testing after any significant modifications.
- Performing regular backups of important data.
- Preparing an incident response plan, and more.
The entire project, from planning to reporting on the results, took 10 days.
The Results
- The Customer received tangible proof of the high security level of its web application.
- The Customer also got actionable guidance on keeping the app protected against potential cyber threats.
Technologies and Tools
Nessus, Burp Suite, Acunetix, DirBuster, Postman, Vooki.