A web application and API penetration test for an agricultural marketplace platform, covering the farmer-facing web platform and every backend API behind it.
System-wide broken access control via a shared API key: a single compromised credential exposed all platform data.
Password hashes exposed in plain text in API responses, letting an attacker crack and hijack any farmer account.
OTP verification bypass via client-side response manipulation, fully circumventing phone and email identity verification.
IDOR in user profiles: any authenticated user could view any other farmer’s personal identity and contact details.
No rate limiting on the login endpoint, leaving accounts vulnerable to brute force and credential stuffing.
A farmer-specific API endpoint accessible with no authentication, making all farmer data readable by anonymous users.
SMS and email OTP flooding: unlimited OTPs triggerable by any user, enabling spam abuse and cost escalation.
A complete security overhaul of the farmer-facing platform: the strongest full-remediation outcome across CredShields’ web application engagement history.
Marketplace platforms with user registration and OTP-based identity flows.
AgriTech and rural-facing digital platforms.
Any B2C or B2B2C platform where user data isolation and identity verification integrity are critical.
As dangerous as the single most exposed place it is used. One shared secret means one leak, one scraped mobile app, or one careless log line compromises every customer’s data at once, not just one account.
Because platforms usually treat OTP verification as the trust anchor for identity, not just a password backstop. Bypassing it lets an attacker claim to be a verified farmer without ever proving phone or email ownership.
Hashing protects passwords at rest, assuming the hash never leaves the database. Returning it in an API response defeats that protection entirely, regardless of how strong the hashing algorithm is.
Every finding, including the critical shared-key issue, was fixed and confirmed on retest with no items left as accepted risk, which is not the case in every engagement.
Tell us what you are securing. We reply with scope and next steps within one business day.
Prefer to see it first? Book a demo ↗
Already a CredShields One customer? Log in ↗