Application Vulnerability Assessment

Web Application Assessment

We conduct vulnerability assessments of web systems through screens where data is exchanged.
By combining automated tool scans with manual assessments, we evaluate whether common attack methods could be used by malicious users to exploit identified risks. If vulnerabilities are detected, we verify that appropriate countermeasures have been implemented after the necessary fixes are made.

Vulnerability Categories
1 Feasibility of Various Injection Attacks
2 Possibility of Cross-Site Scripting (XSS)
3 Authentication Vulnerabilities
4 Inadequate access control
5 Incomplete Authentication and Authorization
6 Inadequate security settings
7 Potential Leakage of Confidential or Sensitive Information
8 Ability to Force Execution of Processes on Authorized Users

API Assessment

For web systems that use APIs as the primary communication hub, we can perform vulnerability assessments not only on the web system’s user interface but also on the APIs themselves.
In API diagnostics, we access the API directly and simulate common attack methods used by malicious users (simulated attacks) to assess security risks.

Vulnerability Categories
1 Feasibility of various injection attacks
2 Feasibility of Cross-Site Scripting
3 Authentication Vulnerabilities
4 Inadequate access control
5 Incomplete Authentication and Authorization
6 Inadequate security settings
7 Potential Leakage of Confidential or Sensitive Information
8 Ability to Force Execution of Processes on Authorized Users

Source Code Analysis

We use tools to scan the source code that makes up the target system to check for risks, visually verify that errors have been removed, and diagnose whether there are any issues with the code.

Details
1 Feasibility of various injection attacks
2 Inadequacies in authentication functions
3 Incomplete Authentication and Authorization
4 Potential Leakage of Confidential or Sensitive Information
5 Ability to Force Execution of Processes on Legitimate Users

Smartphone Application Diagnosis

We use tools to scan the source code that makes up the target system to check for risks, visually verify that errors have been removed, and diagnose whether there are any issues with the code.

Items to be checked Verification Items Verification Details
Source Code Verification Decompilation Feasibility Verify convertibility to Smali files
State of Source Code Obfuscation Check for obfuscation of variable names, functions, etc., by visually inspecting Smali files
Unencrypted Confidential Information in Source Code Check whether entries in the source code that appear to be IDs or passwords are in plain text
Verification of Device Ownership Information File verification through generation, saving, and deletion Iterate through the code and verify files generated on the device Verify residual files upon application termination
Check for the presence of confidential information in files Check various files to verify whether entries that appear to be IDs or passwords are in plain text Check information within SharedPreferences
Check for encryption Verify whether information stored in files is encrypted
Investigate binary files and debug messages Investigate whether any unnecessary information has been left behind As a general rule, visually inspect the contents of files
Configuration and use of control functions Verify file permissions for each file Verify the appropriateness of permission settings
Communication security Certificate verification process Checking whether certificates are verified
Encrypted communication Verify that confidential information (e.g., personal information and UIDs) is transmitted via HTTPS
Communication Sites Verify whether communication occurs with domains other than the expected ones

Security Assessment Service Flow

Web Application Assessment Process

1
Site Review

We will review the target site and conduct an interview.
Please provide the target site and issue a test account.

2
Scope Confirmation

We will create a list of URLs (pages) for the site to be audited.
*We may request test data or similar materials.

3
Proposal

We will submit a proposal outlining the scope and details of the audit, along with a quotation.
We will coordinate the audit schedule with you.

4
Application

Please fill out the required information and send us the order form.
*We may request that you create test data or make configuration changes to your firewall or other systems prior to the start of the assessment.

5
Assessment

If a critical vulnerability is discovered during the assessment, we will notify you via an urgent alert.
*We may ask you to prepare test accounts or similar resources during the assessment.

6
Report

We will submit the assessment report within approximately 5 business days after the assessment is completed.
*We also offer optional briefing sessions.

Please feel free to contact us for detailed service information