Back to Case Studies
Pentest Application Security

Black-Box External Pentest Traces a Single Misconfiguration to Full Source Code and Database Exposure

Found an exposed deployment configuration file that alone handed over the client's full application source code and a database dump — with zero prior access or credentials — inside a broad external attack-surface assessment that also caught the chained flaws needed to turn it into account takeover.

Client: Mid-Market Consumer Goods Company — Public Web Platform

Industry
Consumer Goods · Public-Facing Web Platform
Engagement
Black-box external penetration test · Production environment, unauthenticated, external-attacker simulation
18
Total findings
None
Access required to reach the critical finding
0
Infrastructure-level findings

Challenge

The client runs a public-facing web platform plus a wide footprint of adjacent internet-exposed subdomains and internal tools. They wanted an outside-in view of their real production security posture — how much an anonymous attacker with zero prior access or credentials could actually reach and compromise, not just a checklist of best-practice gaps.

Approach

A pure black-box external assessment against the live production environment, starting from nothing but the root domain — no credentials, no internal access, no advance notice of specific targets beyond what a real attacker could discover through reconnaissance. Testing covered the public web application and its full adjacent subdomain footprint, simulating exactly the access an opportunistic external attacker would have.

Key Activities

  • Mapped the full external attack surface from the root domain outward — subdomains, exposed services, and adjacent internet-facing assets
  • Identified and exploited an exposed deployment-configuration artifact that exposed the application's full source code and a production database dump
  • Chained a reflected XSS finding with missing cookie security attributes to demonstrate practical session and account takeover, not just a theoretical script-injection alert
  • Reviewed authentication flows for password-reset, account-deletion, and session-invalidation gaps
  • Tested for hardcoded credentials and third-party API keys embedded in client-accessible code
  • Delivered a full severity-ranked remediation plan, from the deployment-hygiene root cause down to hardening-level gaps

Results

Found an exposed deployment-configuration file that granted unauthenticated access to the full application source code and a database dump — from a completely anonymous starting position
Identified an outdated internal component with a publicly known privilege-escalation vulnerability, reachable from the internet
Confirmed a reflected XSS finding was practically exploitable for cookie and session theft, due to missing cookie security attributes on the same platform
Found hardcoded third-party API keys embedded directly in client-side code, exposing the client to abuse of paid external services under its own account
Delivered 18 findings across every severity tier, with zero infrastructure-level issues found — isolating the risk cleanly to application and deployment practices

Business Impact

Gave the client a real attacker's-eye view of its production exposure, not a theoretical audit — the source-code and database exposure alone was independently sufficient for full application compromise
Showed exactly how a single deployment-hygiene mistake outweighed otherwise reasonable web security practices, refocusing remediation priority correctly
Delivered a fix roadmap the client's team could execute without guessing which of eighteen findings actually mattered first

Technologies & Service Areas

External Attack Surface Mapping Web Application Testing Black-Box Penetration Testing Deployment Security Review

Related Services

Client names and identifying details are withheld. This case study is a sanitized account shared with the client's consent.