Black-Box External Pentest Traces a Single Misconfiguration to Full Source Code and Database Exposure
Found an exposed deployment configuration file that alone handed over the client's full application source code and a database dump — with zero prior access or credentials — inside a broad external attack-surface assessment that also caught the chained flaws needed to turn it into account takeover.
Client: Mid-Market Consumer Goods Company — Public Web Platform
- Industry
- Consumer Goods · Public-Facing Web Platform
- Engagement
- Black-box external penetration test · Production environment, unauthenticated, external-attacker simulation
Challenge
The client runs a public-facing web platform plus a wide footprint of adjacent internet-exposed subdomains and internal tools. They wanted an outside-in view of their real production security posture — how much an anonymous attacker with zero prior access or credentials could actually reach and compromise, not just a checklist of best-practice gaps.
Approach
A pure black-box external assessment against the live production environment, starting from nothing but the root domain — no credentials, no internal access, no advance notice of specific targets beyond what a real attacker could discover through reconnaissance. Testing covered the public web application and its full adjacent subdomain footprint, simulating exactly the access an opportunistic external attacker would have.
Key Activities
- ▸ Mapped the full external attack surface from the root domain outward — subdomains, exposed services, and adjacent internet-facing assets
- ▸ Identified and exploited an exposed deployment-configuration artifact that exposed the application's full source code and a production database dump
- ▸ Chained a reflected XSS finding with missing cookie security attributes to demonstrate practical session and account takeover, not just a theoretical script-injection alert
- ▸ Reviewed authentication flows for password-reset, account-deletion, and session-invalidation gaps
- ▸ Tested for hardcoded credentials and third-party API keys embedded in client-accessible code
- ▸ Delivered a full severity-ranked remediation plan, from the deployment-hygiene root cause down to hardening-level gaps
Results
Business Impact
Technologies & Service Areas
Related Services
Client names and identifying details are withheld. This case study is a sanitized account shared with the client's consent.