Security Testing on OWASP standards for a Fleet management System

About the client
The client is a provider of Fleet Management Application.
- The client wanted to test the fleet management system which consists of a web application and set of APIs.
- A secure application is required which does not contain any vulnerability and has no risk of any potential threats.
- Lot of data regarding the driver and different user roles is stored in the database.
- Port Scanning is required to find out any which ports on a network are open and could be receiving or sending data.
- OWASP Top 10 Application Security Audit (Manual & Automation) of web application is required
The Challenge
Some of the pages like profile and dashboard were partially developed for most of the user roles, hence it was difficult to effectively complete the testing for the full web application
The scope of API testing was increased in the Re-Validation Round
The testing environment and API details were not provided As per the defined timelines which pushed the end date of the project
The Solution
Services we offered
Security Testing | Test Automation
Outcomes
- During the Detailed security testing (Phase 1), 4 medium risk and 1 low risk vulnerabilities was found.
- At the closure of Re-validation (Phase 2) ,3 medium vulnerabilities and 1 Low vulnerability were fixed.
- 1 medium vulnerability had been marked as an exception which will be re-validated by Intel development team
Key Outcomes
reduction in vulnerabilities of the application