Public Sector Web Application · No Access
Eleven findings. Sixty-one minutes. One database, fully compromised.
A public-facing citizen services portal. We shared no list of its pages or systems in advance. The agent mapped out the site on its own, the way a human tester would, and walked out with the database.
11
Findings
61min
Duration
Crown jewel
Full database read
A database injection flaw (blind SQLi) chained up to full admin rights.
The chain
- 01Map the site.
- 02Probe for weak spots.
- 03Prove the exploit.
- 04Report.
Outcome
Critical findings fixed within the same week. The cross-site sharing rule and the extra-fields flaw (mass assignment) were patched first. The database account was stripped of admin rights the same day the report shipped.