National Technical Research Organisation (NTRO)
Security Assessment of the World Monitor application
Official description
• Background The world Monitor application is a Web/ Mobile platform that provides users with real-time monitoring, analytics, and reporting features. The application handles user authentication, data visualization, API communication, and role-based access controls. As a security analyst, the task is to evaluate the application's security posture and identify vulnerabilities that could compromise the confidentiality, integrity, or availability of the system. • Description Conduct an authorized security assessment of the World Monitor application to: 1. Identify security vulnerabilities in the application. 2. Assess the potential impact of each vulnerability. 3. Demonstrate proof-of-concept exploitation in a controlled environment. 4. Recommend remediation measures to mitigate the identified risks. • Scope The assessment should focus on: • Authentication and session management • Authorization and access control • Input validation and data handling • API security • Client-side security controls • Secure communication mechanisms • Data storage and privacy protections • Success Criteria The assessment is considered successful if: • At least one valid vulnerability is identified and documented. • Evidence supports the existence of the vulnerability. • Risk and impact are clearly explained. • Practical mitigation strategies are provided • Expected Solution/Deliverables: For each vulnerability discovered, provide: • Vulnerability title • Description • Affected component • Severity rating (e.g., CVSS) • Steps to reproduce • Proof of concept demonstrating the issue in a safe testing environment • Business impact assessment • Remediation recommendations constraints • Testing must be performed only on authorized systems. • No actions should affect production users or data. • Exploitation should be limited to proof-of-concept validation. • Compliance with applicable laws, policies, and ethical hacking guidelines is required.