Public Sector Web Application · Black Box
Eleven findings. Sixty-one minutes. One database, fully compromised.
Internet-facing citizen services portal. No prior endpoint inventory shared. The agent mapped the surface on its own, the way a human tester would, and walked out with the database.
11
Findings
61min
Duration
Crown jewel
Full DB read
Blind SQLi chained to a superuser role.
The chain
- 01Reconnaissance.
- 02Probing.
- 03Exploitation.
- 04Report.
Outcome
Critical findings remediated within the same week. Permissive CORS and mass assignment patched first. Database role downgraded from superuser the same day the report shipped.