Back to Case Studies
Pentest Application Security

External Web Pentest Uncovers a Debug Misconfiguration One Step From Remote Code Execution

Found a debug endpoint left enabled in production that disclosed a remote-code-execution capability outright — plus the credential leaks, injection points, and hardening gaps needed to build a realistic end-to-end attack path against a healthcare-adjacent platform.

Client: Healthcare Services Company — Patient-Facing Web Platform

Industry
Healthcare Services · Web Platform
Engagement
Black-box external penetration test · Two production web assets, external-attacker simulation
13
Total findings
1
Critical findings
Zero-credential, fully external
Path to the critical finding

Challenge

The client operates patient-facing web platforms and wanted an external attacker's view of their real-world exposure — starting from nothing but public URLs, the same starting point any opportunistic attacker would have. Given the sensitivity of the data involved, the priority was finding anything that could lead to a full compromise, not just a checklist of missing headers.

Approach

A black-box external penetration test against both production web assets, run exactly as an attacker with zero prior access would operate: reconnaissance and enumeration, automated and manual vulnerability assessment, then exploitation to confirm real impact rather than stopping at theoretical findings. Open-source intelligence gathering was included to check whether employee credentials had already surfaced in prior breaches.

Key Activities

  • Enumerated both production web assets for exposed endpoints, debug interfaces, and outdated components
  • Identified and confirmed a debug/health-check endpoint left enabled in production that explicitly reported command-execution capability
  • Exploited the same debug exposure to pull application source code and database query details normally invisible to an external party
  • Confirmed a reflected XSS vulnerability was practically exploitable, not just theoretically injectable
  • Ran OSINT / breach-database checks against employee email addresses to assess credential-reuse exposure
  • Delivered severity-ranked findings with the debug-mode misconfiguration flagged as the immediate, non-negotiable fix

Results

Found a debug endpoint left enabled in production that directly reported the ability to execute commands — one configuration flag away from full remote code execution
Confirmed the same debug exposure disclosed application source code and database query details to any unauthenticated visitor
Verified a reflected XSS vulnerability was exploitable in the browser, not just theoretically present
Identified employee corporate credentials already circulating in public breach data — a live credential-reuse risk, independent of any application flaw
Delivered 13 findings across every severity tier, headlined by one Critical with a direct, unambiguous path to full compromise

Business Impact

Gave the client unambiguous, evidence-backed urgency on the single fix that mattered most — a debug flag left on in production — rather than a flat list competing for attention
Surfaced a credential-exposure risk entirely outside the application itself, which no code-level fix alone would have caught
Delivered prioritized recommendations the client's team could act on immediately, starting with the one change that closed the critical path

Technologies & Service Areas

External Attack Surface Mapping Web Application Testing OSINT / Credential Exposure Review Black-Box Penetration Testing

Related Services

Client names and identifying details are withheld. This case study is a sanitized account shared with the client's consent.