en

Pentest and Protection of Platform from DDoS

Client:
Financial brokerage company in the online betting sector
 
Industry:
Finance
Focus:
Betting on voting outcomes (primarily political topics)
Main challenge:
Security testing of the web platform after DDoS attacks and implementation of additional protection
Market:
International
Services provided:
Black-box web app pentesting, implementation of Dataguard
Key Takeaways
  • Discovered 30 vulnerabilities in two web applications
  • Implemented DataGuard and Cloudflare for DDoS protection
  • Conducted a black-box pentest of the betting platform
  • Used manual, automated, and OSINT testing methods
  • Prepared a detailed report with recommendations
  • 30
    vulnerabilities discovered
    4
    tools applied
    2
    web applications tested
    Pentest and Protection of Platform from DDoS
    Is there a point in pentesting after DDoS attacks? Yes. To prevent future incidents, the client ordered a black-box pentest, during which 30 vulnerabilities were discovered in the web applications. The implementation of DataGuard and additional protection significantly strengthened the platform.

    The brokerage company developed an online platform where users could create polls and place monetary bets on the outcomes. Web service security was critically important for the client, as they operate in a high-risk financial sector and handle sensitive data.

    After a series of DDoS attacks, the company's product required a thorough assessment of its web applications to enhance cybersecurity and prevent future incidents.

    Tasks and challenges
    The client was concerned about the threat of unauthorized access to the platform and requested a pentest of the website, admin panel, and user interface.
    The company expected to receive a report with results and actionable recommendations that could be used to quickly eliminate risks and strengthen protection.
    • Conduct a black-box pentest to identify potential vulnerabilities
    • Assess the platform's resilience to DDoS attacks, bot traffic, and other threats
    Our approach

    To assess the security of the betting platform, we applied a black-box pentesting strategy along with both automated and manual testing of the web applications. We used OSINT techniques and tools such as Burp Suite, Nessus, and OWASP ZAP to identify both technical and logical vulnerabilities.

    Based on the penetration testing results, the Datami team compiled a report with findings and recommendations. To further enhance protection against DDoS attacks and bots, DataGuard and Cloudflare were implemented.

    Key work stages and solutions

    After thorough preparation, the Datami team conducted full-scale black-box testing: they simulated potential attacks on the web applications and compiled a report on the discovered vulnerabilities.

    A separate stage involved implementing protective solutions, including the integration of DataGuard to defend against DDoS attacks and bots.

    • Preparation
      Analysis of testing objectives, development of attack scenarios, and selection of tools for black-box assessment.
       
    • Security assessment
      Automated and manual testing of two web applications (user/admin), attack simulation without access to source code.
       
    • Results & protection
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations
    Our certificates
    Key project results

    Thanks to the project, 30 vulnerabilities were identified in the betting service, and protection against DDoS attacks was implemented using Dataguard and Cloudflare. As a result, the client achieved a significantly higher level of cybersecurity and platform stability.

    This case study highlights that even smaller market players can become targets for hackers. If your company handles payment information or processes personal data, security testing is essential.

    Category
    Before the project
    After implementation
    Security level
    Unknown, no independent assessment
    Real threat level identified: 30 vulnerabilities discovered
    Vulnerabilities
    Not identified
    Found: 1 high, 7 medium, 19 low, 3 informational
    DDoS protection
    Absent or unstable
    Dataguard and Cloudflare implemented
    Account compromise
    Risk for administrators
    Risk minimized through privilege restrictions
    Unauthorized access
    Potential threat
    Issues with access rights and configurations resolved
    More success stories with Datami
    Browse other project case studies
    P2P Platform Case Study: Comprehensive Security and GDPR Compliance Audit

    P2P Platform Case Study: Comprehensive Security and GDPR Compliance Audit

    • Identified 10 vulnerabilities, including 3 critical ones
    • Improved GDPR compliance and avoided potential financial losses of up to $300,000
    Services:
    Penetration testing, smart contract audit, code security review, testing for SQLi, XSS, and RCE vulnerabilities, OSINT analysis, and cloud infrastructure security assessment
    Jun 27, 2025
    Case Study: Consulting Company – Security Testing of Web Resources and Infrastructure

    Case Study: Consulting Company – Security Testing of Web Resources and Infrastructure

    • Conducted black-box pentest of two web resources and infrastructure components
    • Identified 19 vulnerabilities: 1 critical, 8 medium, 7 low, and 3 informational
    Services:
    Black-box pentest of two web resources with different domain zones (UA and UK), and assessment of related infrastructure components
    Jun 6, 2025
    Case Study Grindset Software: Payment System Pentest for PCI DSS Compliance

    Case Study Grindset Software: Payment System Pentest for PCI DSS Compliance

    • Conducted a black-box penetration test of critical payment system components
    • Discovered 15 vulnerabilities; 5 critical issues were resolved within 48 hours
    Services:
    Black-box penetration testing of the payment system, including assessment of web applications, servers, databases, and communication channels
    May 30, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    First Penetration Test: 7 Unexpected Takeaways for Clients Datami Newsroom
    Datami Newsroom

    First Penetration Test: 7 Unexpected Takeaways for Clients

    Many companies postpone penetration testing due to various fears and misconceptions. However, once they decide to conduct their first test, they receive unexpected results.

    Jul 11, 2025 3 min
    The Enemy Within: Top 5 Insider Cyber Threats for Companies in 2025 Datami Newsroom
    Datami Newsroom

    The Enemy Within: Top 5 Insider Cyber Threats for Companies in 2025

    Company leaders often greatly underestimate insider cyber threats - yet it is employee actions, even unintentional ones, that can lead to catastrophic consequences.

    Jul 8, 2025 3 min
    Top 5 Companies That Refused to Pay Hackers a Ransom Datami Newsroom
    Datami Newsroom

    Top 5 Companies That Refused to Pay Hackers a Ransom

    In May 2025, hackers breached Coinbase, stole data, and demanded a ransom. But the crypto exchange turned to law enforcement for help. This is just one example of how companies are standing up to cyber extortion.

    Jul 4, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy