Unifonic provides companies in the Middle East with seamless, multilingual, enterprise-grade communications at reasonable prices. The business has assisted various organizations in developing efficient customer communication since its founding in 2006. Up until this point, it has served more than 160 million recipients and more than 5000 commercial accounts.
OWASP ZAP: active and passive scanning, fuzzing, and vulnerability detection
Burp Suite: for intercepting requests, manipulating parameters, and scanning for vulnerabilities.
Postman: to identify security weaknesses and validate the behavior of APIs.
Tested API was not secure. It was not aligned with the best security practices.
We highlighted multiple security weaknesses in the said API that might result in catastrophic failures if attacked.
We delivered a thorough report to the client featuring all the exploited vulnerabilities, their impacts, and how to mitigate them.
However, we suggested that analyzing the Client’s API security posture is just one assessment. They should use other elements as well to get a definitive measurement of their security policies.
We recommended a complete review of internal security controls, procedures, or internal red teaming.