Uncovering Hidden Website Security Weaknesses
Plainsight Security conducted a web application penetration test and source code review for Northern Area PGLEL, identifying hidden weaknesses and providing practical guidance to strengthen their website security.
Northern Area PGLEL
Services: Web Application Penetration Testing and Source Code Review
Client: Northern Area PGLEL
The Challenge
Northern Area PGLEL takes the security of its online presence seriously and wanted independent assurance that its public-facing website was appropriately protected.
The website is primarily brochureware, without user accounts, authentication or complex access controls. However, like any system exposed to the internet, it still presents an attack surface that could potentially contain weaknesses.
Northern Area PGLEL therefore engaged Plainsight Security to conduct a web application penetration test, supported by a review of the website's source code.
The objective was straightforward: look at the website from both the outside and the inside to identify security weaknesses that might otherwise go unnoticed.
Our Approach
Plainsight Security assessed the website using a combination of web application penetration testing and source code review.
Web Application Penetration Testing
The live website was examined from the perspective of an external attacker.
Testing considered areas such as:
- Web server and application configuration
- Input handling and validation
- Information disclosure
- HTTP security controls
- Exposed files, directories and functionality
- Software and component security
- Transport security
- Common web application vulnerabilities
- Unexpected application behaviour
Automated tooling was used where appropriate, but the assessment did not rely on scanner results alone.
Potential issues were manually investigated and validated to determine whether they represented genuine security weaknesses and what their practical impact could be.
Source Code Review
Plainsight Security also reviewed the underlying source code to provide an additional perspective on the security of the website.
While penetration testing examines what can be discovered and exploited through the running application, reviewing the source code allows the tester to look beneath the surface.
The review looked for insecure coding practices, potentially dangerous functionality, inappropriate handling of data and other implementation issues that might not be immediately apparent from external testing alone.
Combining the two approaches provided greater visibility than relying on either technique in isolation.
Finding the Weaknesses That Are Easy to Miss
The assessment identified a small number of previously unnoticed weaknesses.
Northern Area PGLEL was able to use the findings and guidance provided by Plainsight Security to quickly and effectively address the issues.
The engagement also demonstrated an important point: a website does not need customer accounts, payment functionality or complex application features to warrant security testing.
Even relatively straightforward public-facing websites can contain weaknesses within their configuration, functionality or underlying code.
By examining both the live website and its source code, Plainsight Security was able to investigate the application from two different perspectives and provide Northern Area PGLEL with a more complete understanding of its security.
From Findings to Remediation
Finding vulnerabilities is only part of a successful security assessment.
The organisation also needs to understand what has been identified, why it matters and what should be done about it.
Plainsight Security provided clear explanations of the issues discovered during testing together with practical remediation guidance.
Northern Area PGLEL was then able to respond quickly and effectively to the findings and strengthen the security of the website.
The Outcome
Following the engagement, Northern Area PGLEL had addressed the weaknesses identified during the assessment and gained greater confidence in the security of its website.
The client subsequently awarded Plainsight Security 5/5 in every category, including:
- Professionalism and conduct
- Technical quality of the service
- Communication throughout the engagement
- Timeliness of delivery
- Clarity and usefulness of reporting
- Overall satisfaction
- Likelihood of recommending Plainsight Security
100% Client Satisfaction
5/5 Professionalism
5/5 Technical quality
5/5 Communication
5/5 Timeliness
5/5 Reporting
5/5 Overall satisfaction
5/5 Likelihood to recommend
What the Client Said
Northern Area PGLEL described the service provided by Plainsight Security as "A1".
"At Northern Area PGLEL, the security of our platform and our users is always a top priority. Recently, we partnered with Plain Sight Securities to conduct a full penetration test on our website.
They expertly identified a few hidden weaknesses, which our team was able to quickly and effectively correct. We are incredibly grateful for the thorough advice and insights we received from them. The entire process was conducted with the utmost professionalism and delivered exactly on time.
A special shoutout goes to Mark, who truly went above and beyond and couldn't do enough for us.
If you are looking to bulletproof your systems, we highly recommend Mark and the team at Plain Sight Securities!"
Andrew Ashton
Northern Area PGLEL
Looking at Security from Both Sides
Traditional web application penetration testing approaches a website in much the same way as an external attacker, interacting with the application and looking for weaknesses that can be discovered from the outside.
Source code review provides another perspective.
Access to the underlying code allows a security tester to investigate how functionality has actually been implemented and identify potential weaknesses that may be difficult to discover through external testing alone.
For Northern Area PGLEL, combining penetration testing with source code review provided a broader assessment of the website's security and helped uncover weaknesses that could then be addressed.
Even Simple Websites Can Have Hidden Weaknesses
A website does not need logins, payment processing or complex functionality to have an attack surface.
Public-facing websites are accessible to everyone, including attackers, and weaknesses in the website, its configuration or its underlying code can potentially create unnecessary security risks.
Plainsight Security provides independent web application penetration testing and source code review to identify those weaknesses, explain their significance and provide practical guidance for fixing them.
If you want to understand what an attacker could discover about your website, contact Plainsight Security to discuss a security assessment.
Andrew Ashton, Area Communications Officer“They expertly identified a few hidden weaknesses, which our team was able to quickly and effectively correct.”
How Northern Area PGLEL rated the engagement
Want results like this?
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.