Web Application Assessment
We conduct vulnerability assessments of web systems through screens where data is exchanged.
By combining automated tool scans with manual assessments, we evaluate whether common attack methods could be used by malicious users to exploit identified risks. If vulnerabilities are detected, we verify that appropriate countermeasures have been implemented after the necessary fixes are made.
| Vulnerability Categories | |
|---|---|
| 1 | Feasibility of Various Injection Attacks |
| 2 | Possibility of Cross-Site Scripting (XSS) |
| 3 | Authentication Vulnerabilities |
| 4 | Inadequate access control |
| 5 | Incomplete Authentication and Authorization |
| 6 | Inadequate security settings |
| 7 | Potential Leakage of Confidential or Sensitive Information |
| 8 | Ability to Force Execution of Processes on Authorized Users |
API Assessment
For web systems that use APIs as the primary communication hub, we can perform vulnerability assessments not only on the web system’s user interface but also on the APIs themselves.
In API diagnostics, we access the API directly and simulate common attack methods used by malicious users (simulated attacks) to assess security risks.
| Vulnerability Categories | |
|---|---|
| 1 | Feasibility of various injection attacks |
| 2 | Feasibility of Cross-Site Scripting |
| 3 | Authentication Vulnerabilities |
| 4 | Inadequate access control |
| 5 | Incomplete Authentication and Authorization |
| 6 | Inadequate security settings |
| 7 | Potential Leakage of Confidential or Sensitive Information |
| 8 | Ability to Force Execution of Processes on Authorized Users |
Source Code Analysis
We use tools to scan the source code that makes up the target system to check for risks, visually verify that errors have been removed, and diagnose whether there are any issues with the code.
| Details | |
|---|---|
| 1 | Feasibility of various injection attacks |
| 2 | Inadequacies in authentication functions |
| 3 | Incomplete Authentication and Authorization |
| 4 | Potential Leakage of Confidential or Sensitive Information |
| 5 | Ability to Force Execution of Processes on Legitimate Users |
Smartphone Application Diagnosis
We use tools to scan the source code that makes up the target system to check for risks, visually verify that errors have been removed, and diagnose whether there are any issues with the code.
| Items to be checked | Verification Items | Verification Details |
|---|---|---|
| Source Code Verification | Decompilation Feasibility | Verify convertibility to Smali files |
| State of Source Code Obfuscation | Check for obfuscation of variable names, functions, etc., by visually inspecting Smali files | |
| Unencrypted Confidential Information in Source Code | Check whether entries in the source code that appear to be IDs or passwords are in plain text | |
| Verification of Device Ownership Information | File verification through generation, saving, and deletion | Iterate through the code and verify files generated on the device Verify residual files upon application termination |
| Check for the presence of confidential information in files | Check various files to verify whether entries that appear to be IDs or passwords are in plain text Check information within SharedPreferences | |
| Check for encryption | Verify whether information stored in files is encrypted | |
| Investigate binary files and debug messages | Investigate whether any unnecessary information has been left behind | As a general rule, visually inspect the contents of files |
| Configuration and use of control functions | Verify file permissions for each file | Verify the appropriateness of permission settings |
| Communication security | Certificate verification process | Checking whether certificates are verified |
| Encrypted communication | Verify that confidential information (e.g., personal information and UIDs) is transmitted via HTTPS | |
| Communication Sites | Verify whether communication occurs with domains other than the expected ones |
Security Assessment Service Flow
Web Application Assessment Process
Site Review
We will review the target site and conduct an interview.
Please provide the target site and issue a test account.
Scope Confirmation
We will create a list of URLs (pages) for the site to be audited.
*We may request test data or similar materials.
Proposal
We will submit a proposal outlining the scope and details of the audit, along with a quotation.
We will coordinate the audit schedule with you.
Application
Please fill out the required information and send us the order form.
*We may request that you create test data or make configuration changes to your firewall or other systems prior to the start of the assessment.
Assessment
If a critical vulnerability is discovered during the assessment, we will notify you via an urgent alert.
*We may ask you to prepare test accounts or similar resources during the assessment.
Report
We will submit the assessment report within approximately 5 business days after the assessment is completed.
*We also offer optional briefing sessions.
Please feel free to contact us for detailed service information