Security Engineering in Internal Processes
Challenge
The client engaged ivision to perform a security assessment of their consumer-facing mobile application with the goal of identifying critical vulnerabilities.
Solution
Despite a seemingly small threat model, the iVision team uncovered methods that allowed attackers to take control of the application’s entire infrastructure, execute arbitrary code on the servers, and gain access to the protected internal network. In addition, the team identified a major flaw that exposed customer PII and enabled the takeover of arbitrary customer accounts. These findings reinforced the importance of integrating security engineering into internal processes and due diligence during acquisitions.