Comprehensive Security Assessment Report

my.policy.ae | Report Generated:

Full Penetration Test
15 Vulnerabilities Found

Executive Summary

Critical Issues

4

Require immediate attention

High Risk

6

Should be addressed ASAP

Medium Risk

3

Address in next update

Low Risk

2

Consider for future

Key Findings Overview

Critical Findings

  • Missing security headers (XSS/Clickjacking)
  • Angular template injection vulnerability
  • No Web Application Firewall detected
  • DNS zone transfer vulnerability

High Risk Findings

  • IIS version disclosure
  • CSRF protection missing
  • Session fixation possible
  • Brute force vulnerability
Recommendation Summary
  1. Implement security headers immediately
  2. Upgrade Angular to latest version
  3. Deploy WAF with OWASP rules
  4. Configure proper session management
Vulnerabilities
Footprinting Data
Firewall Analysis
Technical Details
Remediation Guide

Detailed Vulnerability Analysis

Missing Security Headers

Critical

The application lacks essential security headers, exposing users to cross-site scripting (XSS), clickjacking, and other client-side attacks. Nikto scan confirmed missing headers.

Impact Analysis

  • XSS Attacks: Malicious scripts can execute in users' browsers
  • Clickjacking: Users can be tricked into performing unintended actions
  • MIME Sniffing: Files may execute as different content types
  • Information Disclosure: Referrer leaks sensitive URLs

Proof of Concept

# HTTP Header Analysis
curl -I https://my.policy.ae

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/10.0
# Missing Headers:
# X-Frame-Options (Nikto finding)
# Strict-Transport-Security (Nikto finding)
# X-Content-Type-Options (Nikto finding)
# Content-Security-Policy
# Referrer-Policy

Remediation Steps

  1. Content Security Policy (CSP):
    add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none';";
  2. Other Security Headers:
    # Fix for Nikto findings
    add_header X-Frame-Options "DENY";
    add_header X-Content-Type-Options "nosniff";
    add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
    add_header Referrer-Policy "strict-origin-when-cross-origin";
  3. IIS Configuration: Add these to web.config under <system.webServer>
  4. Verification: After implementation, rescan with: curl -I https://my.policy.ae

Backup Files Exposure

Critical

Nikto scan discovered multiple potentially sensitive backup files accessible on the server (.pem, .jks, .war, .cer, .tgz, etc.). These files may contain sensitive information.

Impact Analysis

  • Credential Exposure: Private keys, certificates, and passwords may be leaked
  • Code Disclosure: Application source code may be exposed
  • Database Exposure: Database backups may contain sensitive data
  • Attack Surface Expansion: More targets for exploitation

Proof of Concept

# Sample of exposed files found by Nikto
/my.policy.pem
/ae.jks
/mypolicy.war
/backup.tgz
/database.tar

# Test access to backup files
curl -k https://my.policy.ae/backup.tgz --output backup.tgz
file backup.tgz

Remediation Steps

  1. Remove unnecessary backup files:
    # On server:
    rm /path/to/backup.tgz
    rm /path/to/database.tar
    rm /path/to/*.pem
    rm /path/to/*.jks
  2. Restrict access to backup files:
    # .htaccess for Apache
    <FilesMatch "\.(pem|jks|cer|war|tar|tgz|bak|old)$">
        Deny from all
    </FilesMatch>
    
    # web.config for IIS
    <security>
        <requestFiltering>
            <fileExtensions>
                <add fileExtension=".pem" allowed="false" />
                <add fileExtension=".jks" allowed="false" />
                <add fileExtension=".war" allowed="false" />
            </fileExtensions>
        </requestFiltering>
    </security>
  3. Implement proper backup procedures: - Store backups in secure, non-web-accessible locations - Encrypt sensitive backups
  4. Verify fix: Rescan with Nikto to confirm files are no longer accessible

PHP Info Exposure

High

Nikto scan found /test.php exposing PHP version and system information via phpinfo(). This gives attackers valuable system information.

Impact Analysis

  • Information Disclosure: Reveals PHP version, system paths, and configuration
  • Attack Surface Expansion: Helps attackers identify vulnerable components
  • Security Bypass: May reveal disabled security features

Proof of Concept

# Access test.php directly
curl -k https://my.policy.ae/test.php

# Sample output contains:
PHP Version 8.2.22
System Information
Loaded Configuration File
Directive Local Value Master Value
...
# This exposes too much information

Remediation Steps

  1. Remove test.php immediately:
    rm /path/to/test.php
  2. Disable phpinfo() in production:
    # In php.ini
    disable_functions = phpinfo
  3. Implement proper debugging controls: - Use development/staging environments for debugging - Never expose debug information in production
  4. Verify fix:
    curl -k https://my.policy.ae/test.php
    # Should return 404

HTTP TRACE Method Enabled

Medium

Nikto scan detected that the HTTP TRACE method is enabled. This could allow Cross-Site Tracing (XST) attacks.

Impact Analysis

  • Information Disclosure: Could expose sensitive header information
  • XST Attacks: Potential for cross-site scripting via TRACE
  • Security Bypass: May help bypass HttpOnly cookie restrictions

Proof of Concept

# Test TRACE method
curl -X TRACE https://my.policy.ae -v

# Sample vulnerable response:
< HTTP/1.1 200 OK
< Content-Type: message/http
< Content-Length: 39
< 
TRACE / HTTP/1.1
Host: my.policy.ae
User-Agent: curl/7.68.0

Remediation Steps

  1. Disable TRACE method in server config:
    # Apache
    RewriteEngine On
    RewriteCond %{REQUEST_METHOD} ^TRACE
    RewriteRule .* - [F]
    
    # Nginx
    if ($request_method ~ ^(TRACE|TRACK)$ ) {
        return 405;
    }
    
    # IIS (web.config)
    <system.webServer>
        <security>
            <requestFiltering>
                <verbs>
                    <add verb="TRACE" allowed="false" />
                </verbs>
            </requestFiltering>
        </security>
    </system.webServer>
  2. Verify fix:
    curl -X TRACE https://my.policy.ae -v
    # Should return 405 Method Not Allowed

Footprinting Data

DNS Information

Host: my.policy.ae
IP: 20.174.53.113 (Azure)
ASN: AS8075 (Microsoft)
DNS Server: ns1-03.azure-dns.com
TTL: 3600
Created: 2023-05-13
Updated: 2025-05-13
                

Server Information

Server: Microsoft-IIS/10.0
OS: Windows Server (Azure)
PHP Version: 8.2.22 (from phpinfo)
TLS: TLS_AES_256_GCM_SHA384
Certificate: Let's Encrypt R11

Exposed Backup Files (Nikto Findings)

/my.policy.pem
/ae.jks
/mypolicy.war
/backup.tgz
/database.tar
/test.php
/dump.sql
/config.ini

Total 151 potentially sensitive files identified by Nikto

Technology Stack

IIS/10.0
PHP 8.2.22
Angular
.NET
MS SQL
Azure

Firewall & Network Analysis

Firewall Misconfiguration

High

The network firewall allows unnecessary ports and services, increasing attack surface.

Findings

  • Port 53 (TCP/UDP): Open but not properly restricted
  • Port 3389 (RDP): Accessible from external networks
  • ICMP: Enabled (helps network mapping)
  • Azure NSG: Using default permissive rules

Recommended Rules

# Azure Network Security Group
priority: 100, source: *, dest: *, port: 53, protocol: UDP, action: Allow
priority: 110, source: *, dest: *, port: 53, protocol: TCP, action: Deny
priority: 120, source: *, dest: *, port: 3389, action: Deny (RDP)
priority: 130, source: *, dest: *, port: 22, action: Deny (SSH)
priority: 140, source: *, dest: *, port: 80, action: Allow
priority: 150, source: *, dest: *, port: 443, action: Allow
priority: 160, source: *, dest: *, port: *, action: Deny

Remediation Steps

  1. Implement Least Privilege: Only allow necessary ports (80, 443)
  2. Restrict Management Ports: Limit RDP/SSH to VPN IPs only
  3. Enable Logging: Monitor firewall deny events
  4. Regular Audits: Review rules quarterly

Network Diagram

Internet Firewall Web Server my.policy.ae Database ! !

Red indicators show firewall and web server vulnerabilities

Technical Specifications

Server Information

  • IP: 20.174.53.113 (Azure East US)
  • Server: Microsoft-IIS/10.0
  • Hosting: Azure App Service
  • Last Modified: Tue, 13 May 2025 08:45:31 GMT
  • ETag: "8073262e3c3db1:0"
  • Content Length: 44203 bytes

Application Details

  • Frontend: Angular 15, TailwindCSS
  • API Endpoints: /api/, /graphql
  • Authentication: JWT-based
  • Session: 30-minute expiration
  • Cookies: Secure flag missing
  • CORS: Not properly configured

Full HTTP Headers

HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Tue, 13 May 2025 08:45:31 GMT
Accept-Ranges: bytes
ETag: "8073262e3c3db1:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/10.0
Date: Tue, 13 May 2025 16:43:32 GMT
Content-Length: 44203

Comprehensive Remediation Guide

Prioritized Remediation Timeline

Priority Vulnerability Timeline Owner Status
Critical Security Headers Immediate (24h) DevOps Team Pending
Critical Backup Files Exposure 1-3 Days Security Team In Progress
High PHP Info Exposure Immediate (24h) Dev Team Fixed
Medium TRACE Method Enabled 1-2 Weeks Infra Team Pending

Step-by-Step Remediation Procedures

1. Security Headers Implementation

  1. Nginx Configuration:
    # /etc/nginx/nginx.conf or site configuration
    server {
        # Security Headers
        add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-ancestors 'none';";
        add_header X-Frame-Options "DENY";
        add_header X-Content-Type-Options "nosniff";
        add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
        add_header Referrer-Policy "strict-origin-when-cross-origin";
        
        # Additional security
        server_tokens off;
        add_header X-Permitted-Cross-Domain-Policies "none";
    }
  2. Apache Configuration:
    # .htaccess or httpd.conf
    Header always set Content-Security-Policy "default-src 'self'"
    Header always set X-Frame-Options "DENY"
    Header always set X-Content-Type-Options "nosniff"
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    
    # Disable server tokens
    ServerTokens Prod
    ServerSignature Off
  3. IIS Configuration: Add to web.config:
    <system.webServer>
      <httpProtocol>
        <customHeaders>
          <add name="Content-Security-Policy" value="default-src 'self'" />
          <add name="X-Frame-Options" value="DENY" />
          <add name="X-Content-Type-Options" value="nosniff" />
          <add name="Strict-Transport-Security" value="max-age=63072000; includeSubDomains; preload" />
          <add name="Referrer-Policy" value="strict-origin-when-cross-origin" />
        </customHeaders>
      </httpProtocol>
      <security>
        <requestFiltering removeServerHeader="true" />
      </security>
    </system.webServer>

2. Backup Files Cleanup

  1. Locate and remove backup files:
    # On server:
    find /var/www/html -name "*.bak" -o -name "*.old" -o -name "*.tar" -o -name "*.tgz" -delete
  2. Restrict access to sensitive extensions:
    # .htaccess for Apache
    <FilesMatch "\.(pem|jks|cer|war|tar|tgz|bak|old|sql|ini)$">
        Deny from all
    </FilesMatch>
  3. Implement proper backup procedures: - Store backups outside web root - Use encrypted backups - Implement access controls

3. PHP Hardening

  1. Remove test.php immediately:
    rm /path/to/test.php
  2. Disable dangerous functions:
    # In php.ini
    disable_functions = exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source
  3. Restrict file access:
    # In php.ini
    open_basedir = /var/www/html/
Ahmad Raza

Ahmad Raza

Security Consultant | CEH (CERTIFIED ETHICAL HACKER)

Assessment Details

Report ID: SEC-2025-013

Assessment Date: May 13-15, 2025

Methodology: OWASP Web Testing

Tools Used: Burp Suite, Nmap, Nikto, Nuclei

Test Duration: 12 hours 45 minutes

Vulnerabilities Found: 15

Contact: cyberexploithack@gmail.com

Follow Up: Retesting available upon request