Adversarial Assurance Report
Proof-of-exploit penetration test & regulatory attestation
| Client / Target | VAmPI (third-party target) |
|---|---|
| Operation ID | OP-20260913-033940 |
| Report Generated (UTC) | 2026-09-13T03:39:46Z |
| Assessment Mode | Air-gapped · shadow-range · production financial ceiling S$0 |
| Classification | Confidential — restricted to authorized recipients |
This document contains confidential security findings intended solely for the named client and its authorized advisors. Distribution, reproduction, or disclosure to any other party without written consent is prohibited. Handle in accordance with the client's information classification policy.
Executive Summary
This engagement confirmed 12 exploitable weaknesses across the VAmPI (third-party target) attack surface, of which 5 critical and 3 high-severity findings present immediate risk to the business. The highest-priority issue, AXM-API2-006, (Forgeable session tokens: JWT signed with a weak, guessable secret) enables full account takeover and was independently re-executed to eliminate doubt about its validity. Collectively, the confirmed defects place the following business outcomes within reach of an unauthenticated or low-privileged attacker: customer data exposure, privilege escalation, account takeover, account integrity loss. Every finding in this report was proven by exploitation and re-verified by independent replay; 0 false positives were reported. Each entry carries a cryptographically sealed evidence capsule that verifies offline.
Methodology. Testing followed NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) and the OWASP Web Security Testing Guide (WSTG) with mapping to the OWASP API Security Top 10 (2023). Findings are admitted only after proof-by-exploitation and independent replay verification; unconfirmed candidates are discarded rather than reported.
Findings Register
Findings are ordered by attacker priority (descending). Each entry is a self-contained, independently reproducible proof of exploitation.
Forgeable session tokens: JWT signed with a weak, guessable secret
BOLA account takeover: any user can reset another user's password
BOLA: any user can change another user's email
SQL injection at /users/v1/
Mass assignment allows self-granting 'admin' on registration
Sensitive data exposed without authentication at /users/v1/_debug
Debug mode enabled: verbose stack traces / interactive debugger exposed
Undocumented / legacy endpoint reachable: /users/v1/_debug
No rate limiting on /users/v1/login — brute-force / credential-stuffing enabler
Undocumented / legacy endpoint reachable: /console
Missing HTTP security headers
Verbose server/version banner disclosure
Regulatory Attestation
A single, independently verified evidence base is mapped to the control clauses of each applicable regime below. One proof of exploitation satisfies the evidentiary requirement across multiple frameworks simultaneously.
| Framework | Clause / Control | Weakness ID | Invariant | Finding |
|---|---|---|---|---|
| OWASP API | API3:2023 | AXM-API3-001 | API3:2023 Excessive Data Exposure | Sensitive data exposed without authentication at /users/v1/_debug |
| API6:2023 | AXM-API6-002 | API6:2023 Mass Assignment | Mass assignment allows self-granting 'admin' on registration | |
| API1:2023 | AXM-API1-003 | API1:2023 Broken Object Level Authorization | BOLA account takeover: any user can reset another user's password | |
| API1:2023 | AXM-API1-004 | API1:2023 Broken Object Level Authorization | BOLA: any user can change another user's email | |
| API8:2023 | AXM-API8-005 | API8:2023 Injection | SQL injection at /users/v1/ | |
| API2:2023 | AXM-API2-006 | API2:2023 Broken Authentication | Forgeable session tokens: JWT signed with a weak, guessable secret | |
| API8:2023 | AXM-API8-007 | API8:2023 Security Misconfiguration | Debug mode enabled: verbose stack traces / interactive debugger exposed | |
| API4:2023 | AXM-API4-008 | API4:2023 Unrestricted Resource Consumption | No rate limiting on /users/v1/login — brute-force / credential-stuffing enabler | |
| API9:2023 | AXM-API9-009 | API9:2023 Improper Inventory Management | Undocumented / legacy endpoint reachable: /users/v1/_debug | |
| API9:2023 | AXM-API9-010 | API9:2023 Improper Inventory Management | Undocumented / legacy endpoint reachable: /console | |
| API8:2023 | AXM-API8-011 | API8:2023 Security Misconfiguration | Missing HTTP security headers | |
| API8:2023 | AXM-API8-012 | API8:2023 Security Misconfiguration | Verbose server/version banner disclosure | |
| PDPA | Protection | AXM-API3-001 | API3:2023 Excessive Data Exposure | Sensitive data exposed without authentication at /users/v1/_debug |
| MAS TRM | 8.4 | AXM-API6-002 | API6:2023 Mass Assignment | Mass assignment allows self-granting 'admin' on registration |
| 13.2.4 | AXM-API1-003 | API1:2023 Broken Object Level Authorization | BOLA account takeover: any user can reset another user's password | |
| 13.2.4 | AXM-API1-004 | API1:2023 Broken Object Level Authorization | BOLA: any user can change another user's email | |
| 9.1 | AXM-API2-006 | API2:2023 Broken Authentication | Forgeable session tokens: JWT signed with a weak, guessable secret | |
| 13.2.4 | AXM-API4-008 | API4:2023 Unrestricted Resource Consumption | No rate limiting on /users/v1/login — brute-force / credential-stuffing enabler | |
| 13.1.1 | AXM-API9-009 | API9:2023 Improper Inventory Management | Undocumented / legacy endpoint reachable: /users/v1/_debug | |
| 13.1.1 | AXM-API9-010 | API9:2023 Improper Inventory Management | Undocumented / legacy endpoint reachable: /console | |
| PCI DSS 4.0 | 6.2.4 | AXM-API1-003 | API1:2023 Broken Object Level Authorization | BOLA account takeover: any user can reset another user's password |
| 6.2.4 | AXM-API1-004 | API1:2023 Broken Object Level Authorization | BOLA: any user can change another user's email | |
| 6.2.4 | AXM-API8-005 | API8:2023 Injection | SQL injection at /users/v1/ | |
| 8.3 | AXM-API2-006 | API2:2023 Broken Authentication | Forgeable session tokens: JWT signed with a weak, guessable secret | |
| 6.2.4 | AXM-API8-007 | API8:2023 Security Misconfiguration | Debug mode enabled: verbose stack traces / interactive debugger exposed | |
| 6.2.4 | AXM-API8-011 | API8:2023 Security Misconfiguration | Missing HTTP security headers | |
| 6.2.4 | AXM-API8-012 | API8:2023 Security Misconfiguration | Verbose server/version banner disclosure |
Evidence Integrity
Every finding above is bound into a hash-chained evidence ledger, sealed to a hardware/software root of trust. The chain and its signature verify entirely offline, without contacting the tester or any external service.
| Merkle root hash | d08073c33ad3adc392f1e67095f0e84f0bddc5ad441d70e62384e9ee98991c87 |
|---|---|
| Root of trust | software (Ed25519) — POC only |
| Signing device serial | SOFT-KEY-0001 |
| Signature | 007435816bff12c42db43c33cf80bc5d… |
The evidence chain and cryptographic signature verify offline: any tampering with a finding, transcript, or digest invalidates the root hash and the signature over it.