Utility Network Security
Working with a large regional utility company, DISD performed a "blind" external penetration test and dial-up connection security assessment. DISD performed realistic, unassisted target reconaissance and enumeration activities, pausing briefly to verify the identified targets before continuing with the external testing. Concurrently utilizing dozens of leased Voice-over-IP (VoIP) provider lines, DISD enumerated and fingerprinted over 50,000 DID numbers over the course of a week, and identified weak authentication credentials for several connected systems, left unprotected by modern network security defenses.
Hospital Site Survey
DISD performed a wireless site survey, identifying potential rogue access points, and wireless network and client penetration test at a hospital campus. This project uncovered insecure authentication mechanisms, weak encryption protocols, and network segmentation issues. DISD provided tailored recommendations to the client to address each of these issues, including Active Directory Group Policy guidance to deploy hardened wireless settings for several thousand client systems.
Ticket Company Data Processing Tests
DISD assisted a major ticket sales and distribution company in their PCI compliance efforts by performing penetration tests for a wide variety of cardholder data-processing applications. These ran the gamut from legacy thick client applications, dealing with issues such as connectionless transport protocols and insecure local storage to web applications and web services facing SQL injection, to interactive voice response (IVR) systems and Kiosk interfaces affected by parameter tampering issues.
Electronic Health Record Beta Testing
DISD performed pre-deployment penetration tests for an electronic health record (EHR) software-as-a-service (SaaS) provider during their beta testing period. This engagement included authenticated testing of multiple web applications and services, as well as the supporting infrastructure. DISD also performed post-remediation testing, and provided a letter of attestation describing the testing scope, methodologies, original results and post-remediation results, allowing the provider to demonstrate their commitment to secure development processes.
Banking Fraud Detection
DISD developed security information management device integration modules for an international banking client, to capture credit and debit transaction data. This data was utilized to help develop and improve proactive fraud detection systems, and to provide detailed audit evidence for investigations.