Skip to main content
 
us

  • Increase Speed to Market
    Deliver quality quicker by optimising your delivery pipeline, removing bottlenecks, getting faster feedback from customers and iterating quickly.

  • Enhance Customer Experience
    Delight your customers in every digital interaction by optimising system quality and performance to provide a smooth, speedy and seamless user experience.

  • Maximise Your Investment
    Realise a positive ROI sooner and maximise your investment by focusing your energy on high-value features, reducing waste, and finding and fixing defects early.
  • The Wellington City Council (WCC) wanted to deliver quality outcomes without breaking the bank. Find out how Planit’s fast and flexible resources helped WCC achieve this goal.

this is a test Who We Are Landing Page


INSIGHTS / Case Studies

Resolving Website Vulnerabilities Before Go-Live

 26 Oct 2021 
Resolving Website Vulnerabilities Before Go-Live Resolving Website Vulnerabilities Before Go-Live
Resolving Website Vulnerabilities Before Go-Live
INSIGHTS / Case Studies

Resolving Website Vulnerabilities Before Go-Live

 26 Oct 2021 

How penetration testing helped this logistics company resolve critical website security vulnerabilities prior to go-live.
 
Security is on everyone’s mind now, more than ever. High profile cyberattacks and ransomware are now a daily occurrence in our news feeds. While there are tools out there to assist with penetration testing, there are issues that only a security specialist is unable to uncover.
 
A recent example of this was with a Planit customer, a major logistics company, who had performed an internal penetration test using off the shelf software and approached Planit to validate their results. The review uncovered that all testing was performed in the UAT environment that did not have the same high availability configuration as production. This raised a red flag for our experienced consultants who encouraged the customer to perform additional validation on their production infrastructure.
 
During manual testing, a high severity defect was discovered as a direct result of the high availability configuration. This setup exposed a vulnerability in the authentication mechanism and allowed the Planit security team to manipulate login sessions to gain full control of the website. Had this issue been exploited in production, it would have caused a significant loss of revenue and reputation for our customer.
 
This issue would not have been detected if the website was simply tested in a UAT environment, or via automated tools alone. It was the in-depth nature of our penetration testing, and years of experience that enabled us to uncover this potentially critical issue.
 
Luckily for our client this issue was discovered before go-live and were able to quickly resolve the issue for retesting as Planit provided detailed steps to reproduce the vulnerability.
 
If you have critical applications, Planit strongly recommends that you augment your automated penetration testing tools with experienced security consultants to ensure that you aren’t left vulnerable.
 

Protect Your Data and Reputation

We can help you protect your valuable assets and brand reputation. Following an international best practice methodical approach, we provide you with in-depth reports into weaknesses that attackers could exploit in your specific systems. We can then work with you to close these loopholes.
 
Find out how Planit’s three-pronged approach to security testing can help you protect your systems by addressing development, use, and infrastructure.

 

Find out more
Key Outcomes:
  • Critical unauthorised access issue uncovered by penetration testing.
  • Issue immediately resolved by the development team.

Delivered:
  • Security Testing
  • Penetration Testing
  • Outcome Based

Technologies:
  • Silverstripe CMS
  • Amazon Web Services

Tools:
  • Acunetix
  • Burp Suite Professional
  • SQLmap
  • Nikto
  • Atlassian Jira
Download Full Case Study