- Objective
- Run a scheduled security assessment of the call-center's web infrastructure serving 300,000 customers
- Path
- The assessment uncovered a critical SQL injection in the client's web application. Through it we reached the database and dumped administrator password hashes. The chain continued: one hash was cracked, we logged into the server — and found that an attacker could already have entrenched themselves there: a task running daily as root kept a backdoor open. Pushing the attack further, we took control of the server and several CRM systems — then stopped and handed everything to the client's team: the vulnerability, the attack path, the affected systems.
- Detected
- The injection was never detected at the edge, and the daily root task looked like routine automation and raised no alerts
After: Together with the client's team we closed the injection, hardened the server and removed the backdoor. The breach of 300,000+ customer records was prevented before it could be used: the company avoided regulatory fines, a reputational crisis and the loss of subscriber trust.