Skip to content
AAAhtisham Ashraf
000

Project 06

Fintech Security Assessment

API, Mobile & Cloud Security Review

Context
Quake Mining
Period
2019
Categories
API Security · Mobile Security · Cloud Security · Fintech

Overview

A security engagement across a fintech and cryptocurrency platform, covering the web application, API surface, mobile applications and cloud configuration, with architectural guidance alongside the findings.

Challenge

A fintech platform with web, API and mobile clients has three views of the same business logic, and they rarely agree on where authorisation is enforced. Assessing them in isolation misses exactly the class of issue that matters most. The engagement needed to look across the surfaces and at the cloud configuration underneath them.

Role

Security auditor — application, API, mobile and cloud assessment with architectural recommendations.

Architecture

  1. 01

    Web Application

    Assessment of the application surface and its security controls.

  2. 02

    API Layer

    Review of API authorisation, exposure and consistency across clients.

  3. 03

    Mobile Clients

    Mobile application security review across the client surface.

  4. 04

    Cloud Configuration

    Cloud hardening review covering exposure and access configuration.

Conceptual only. No real topology, configuration or internal architecture is described.

Solution

  • Cross-surface assessment covering web, API, mobile and cloud.
  • Architectural recommendations addressing where controls should sit.
  • Cloud hardening guidance for the platform team.

Security

  • This entry describes the engagement only. No vulnerability details, reproduction steps or exploit information are published.

Outcome

  • Vulnerabilities identified across the web, API and mobile surfaces.
  • Cloud hardening and security architecture recommendations delivered.

Lessons

  • When three clients share one backend, authorisation belongs in exactly one of them — the backend.
  • Cloud misconfiguration is quieter than an application bug and frequently more expensive.