Pandora consultants had performed a fast-track Security Risk Assessment focusing on the protection of business information with the client and understand where was the highest risk area for the suspected information disclosure.
3 servers hosting company ERP/CRM applications and databases were identified and concurrent Internal Penetration Test against the servers and the Computer Forensics work on the servers were performed.
It was then identified from the Internal Penetration Test that the application suffered from a username enumeration vulnerability that administrative users could easily be figured out. Also, on top of that, there was an administrator with a very weak password.
Combined with the information obtained in the Internal Penetration Test and the traces and data obtained after the Computer Forensics work, the consultant identified and locked down an internal user with evidence (IP information and time and data accessed) that the user purposely guessed the password of the administrative user and performed unauthorized access to the applications.
Pandora was not informed about the fate of the internal staff who performed the security breach but was praised as very helpful to find out the root cause and the evidence for stopping the further potential damage.
This was quite a serious case that the criminals involved were cross-border. The jewelry company was very nervous to know the root cause why the fraudsters had a list of their clients and could be able to trick some of the clients to pay to the fraudulent accounts.
Pandora performed a Security Risk Assessment on the workflow of the jewelry company and identified quite a number of deficiencies.
The company staff members communicate with their clients and buyers using email without encryption or a secure mechanism and they usually send money request to the clients by email request only.
Pandora consultant had performed the Emergent Security Inspection and helped to identified that the email account of one of the staff members were compromised by rootkit backdoor software such that the hackers might have observed and identified the weakness of the money transaction process of the company and thus successful in launching the attacks.
Pandora consultant performed a full review on the workflow of the jewelry company and suggested to re-engineer it according to the newly drafted Security Policy and Documentations recommended to the compnay including the use of secure email and a more secure money transaction mechansim.
Also, Security Product Integration was performed by Pandora to strengthen the security and protection of the endpoints of the company by deploying and configuring of endpoint protection software and next-generation firewall to block attacks at network level.
The Baseline Security Configuration work was not simply grabbing the well known baseline configurations from the authoritative bodies and forcefully push the company to enforce them. This will be of least value to the client for performing Baseline Security Configuration.
Instead, Pandora consultant conducted interviews and research with different departments and users of the securities firm to understand the requirements for arriving the sets of configurations which are feasible and still secure enough to protect the information assets of the firm.
For items and configurations that were not implemented in the baseline, Security Risk Assessment on was performed to analyze the risk and document the rationale why it is acceptable. Also, complementary control was documented.
For the exercise, Pandora had arrived five sets of usable baseline configurations (Windows Server 2012, Windows Server 2008 R2, VMware ESXi 6.0, Redhat Enterprise Linux 5 and Oracle Solaris 10) satisfying the expectation from security team, IT operations team and the development teams of the securities firm.