en

Pentest and Protection of Platform from DDoS

Client:
Financial brokerage company in the online betting sector
 
Industry:
Finance
Focus:
Betting on voting outcomes (primarily political topics)
Main challenge:
Security testing of the web platform after DDoS attacks and implementation of additional protection
Market:
International
Services provided:
Black-box web app pentesting, implementation of Dataguard
Key Takeaways
  • Discovered 30 vulnerabilities in two web applications
  • Implemented DataGuard and Cloudflare for DDoS protection
  • Conducted a black-box pentest of the betting platform
  • Used manual, automated, and OSINT testing methods
  • Prepared a detailed report with recommendations
  • 30
    vulnerabilities discovered
    4
    tools applied
    2
    web applications tested
    Pentest and Protection of Platform from DDoS
    Is there a point in pentesting after DDoS attacks? Yes. To prevent future incidents, the client ordered a black-box pentest, during which 30 vulnerabilities were discovered in the web applications. The implementation of DataGuard and additional protection significantly strengthened the platform.

    The brokerage company developed an online platform where users could create polls and place monetary bets on the outcomes. Web service security was critically important for the client, as they operate in a high-risk financial sector and handle sensitive data.

    After a series of DDoS attacks, the company's product required a thorough assessment of its web applications to enhance cybersecurity and prevent future incidents.

    Tasks and challenges
    The client was concerned about the threat of unauthorized access to the platform and requested a pentest of the website, admin panel, and user interface.
    The company expected to receive a report with results and actionable recommendations that could be used to quickly eliminate risks and strengthen protection.
    • Conduct a black-box pentest to identify potential vulnerabilities
    • Assess the platform's resilience to DDoS attacks, bot traffic, and other threats
    • Deliver a report with findings and recommendations for cybersecurity improvements
    icon
    Penetration testing
    Black-box pentest of two web applications to assess resistance to external attacks
    icon
    Dataguard implementation
    DDoS protection and malicious traffic filtering solution
    icon
    Report and recommendations
    Test results summary and recommended actions to eliminate vulnerabilities
    Our approach

    To assess the security of the betting platform, we applied a black-box pentesting strategy along with both automated and manual testing of the web applications. We used OSINT techniques and tools such as Burp Suite, Nessus, and OWASP ZAP to identify both technical and logical vulnerabilities.

    Based on the penetration testing results, the Datami team compiled a report with findings and recommendations. To further enhance protection against DDoS attacks and bots, DataGuard and Cloudflare were implemented.

    Black-box
    Black-box
    Assessment from the perspective of an external attacker - without access to source code or internal information
    Key work stages and solutions

    After thorough preparation, the Datami team conducted full-scale black-box testing: they simulated potential attacks on the web applications and compiled a report on the discovered vulnerabilities.

    A separate stage involved implementing protective solutions, including the integration of DataGuard to defend against DDoS attacks and bots.

    • Preparation
      Analysis of testing objectives, development of attack scenarios, and selection of tools for black-box assessment.
       
    • Security assessment
      Automated and manual testing of two web applications (user/admin), attack simulation without access to source code.
       
    • Results & protection
      Risk evaluation, report preparation with technical details and recommendations. DataGuard implementation.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    During the testing of the betting platform, the Datami team discovered 30 vulnerabilities: 1 high, 7 medium, 19 low, and 3 informational. These affected both technical configurations and access to functionality in the user and admin areas.

    Based on the pentest results, we prepared a report and provided recommendations to enhance digital security:

    1. configure bot and DDoS protection using DataGuard and Cloudflare;
    2. fix incorrect access configurations;
    3. strengthen control over administrative privileges.

    Most vulnerabilities were addressed immediately, significantly increasing the platform’s overall security level.

    Our certificates
    Key project results

    Thanks to the project, 30 vulnerabilities were identified in the betting service, and protection against DDoS attacks was implemented using Dataguard and Cloudflare. As a result, the client achieved a significantly higher level of cybersecurity and platform stability.

    This case study highlights that even smaller market players can become targets for hackers. If your company handles payment information or processes personal data, security testing is essential.

    Category
    Before the project
    After implementation
    Security level
    Unknown, no independent assessment
    Real threat level identified: 30 vulnerabilities discovered
    Vulnerabilities
    Not identified
    Found: 1 high, 7 medium, 19 low, 3 informational
    DDoS protection
    Absent or unstable
    Dataguard and Cloudflare implemented
    Account compromise
    Risk for administrators
    Risk minimized through privilege restrictions
    Unauthorized access
    Potential threat
    Issues with access rights and configurations resolved
    More success stories with Datami
    Browse other project case studies
    P2P Platform Case Study: GDPR Compliance Audit

    P2P Platform Case Study: GDPR Compliance Audit

    • Improved GDPR compliance and avoided potential losses
    • Identified 10 vulnerabilities, including 3 critical ones
    Services:
    Penetration testing, smart contract audit, code security review
    Jun 27, 2025
    Case Study: Consulting Company Security Test

    Case Study: Consulting Company Security Test

    • Identified 19 vulnerabilities, including 1 critical, and 8 medium
    • Provided security compliance recommendations
    Services:
    Black-box pentest of web resources and infrastructure
    Jun 6, 2025
    Payment System Pentest for PCI DSS Compliance

    Payment System Pentest for PCI DSS Compliance

    • Discovered 15 vulnerabilities, including 5 critical issues
    • Improved attack resilience by 85%
    Services:
    Black-box pentest web applications, servers
    May 30, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Ingram Micro confirms ransomware attack Datami Newsroom
    Datami Newsroom

    Ingram Micro confirms ransomware attack

    California-based company Ingram Micro, headquartered in Irvine, California, has reported the discovery of ransomware in its internal systems. The attackers caused a disruption in order processing.

    Jul 31, 2025 3 min
    Automation vs. Pentesters: Can AI Replace Humans? Datami Newsroom
    Datami Newsroom

    Automation vs. Pentesters: Can AI Replace Humans?

    Every year, companies are increasingly integrating automated tools into their cybersecurity processes. Automation is just one auxiliary tool that comes with both advantages and disadvantages that must be kept in mind.

    Jul 25, 2025 3 min
    Aviation and Cyber Threats: TOP Hacker Attacks on Airports and Aircraft Datami Newsroom
    Datami Newsroom

    Aviation and Cyber Threats: TOP Hacker Attacks on Airports and Aircraft

    The aviation industry is one of the most technologically advanced sectors, significantly influenced by digitalization. At the same time, this increases its vulnerability to cyber threats, which can have catastrophic consequences.

    Jul 23, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy