en

Stability and Security for Real-Time Trading

Client:
Financial brokerage company in the online betting sector
 
Industry:
Finance
Focus:
Betting on voting outcomes (primarily political topics)
Main challenge:
Security testing of the web platform after DDoS attacks and implementation of additional protection
Market:
International
Services provided:
Black-box web app pentesting, implementation of Dataguard
Key Takeaways
  • Hardened two web apps and APIs against exploits and DDoS
  • Maintained full service availability
  • Discovered 30 vulnerabilities in two web applications
  • Used manual, automated, and OSINT testing methods
  • Prepared a detailed report with recommendations
  • 30
    vulnerabilities discovered
    4
    tools applied
    2
    web applications tested
    Stability and Security for Real-Time Trading
    Is there a point in pentesting after DDoS attacks? Yes. To prevent future incidents, the client ordered a black-box pentest, during which 30 vulnerabilities were discovered in the web applications. The implementation of DataGuard and additional protection significantly strengthened the platform.

    The brokerage company developed an online platform where users could create polls and place monetary bets on the outcomes. Web service security was critically important for the client, as they operate in a high-risk financial sector and handle sensitive data.

    After a series of DDoS attacks, the company's product required a thorough assessment of its web applications to enhance cybersecurity and prevent future incidents.

    Tasks and challenges
    The client was concerned about the threat of unauthorized access to the platform and requested a pentest of the website, admin panel, and user interface.
    The company expected to receive a report with results and actionable recommendations that could be used to quickly eliminate risks and strengthen protection.
    • Conduct a black-box pentest to identify potential vulnerabilities
    • Assess the platform's resilience to DDoS attacks, bot traffic, and other threats
    • Deliver a report with findings and recommendations for cybersecurity improvements
    icon
    Penetration testing
    Black-box pentest of two web applications to assess resistance to external attacks
    icon
    Dataguard implementation
    DDoS protection and malicious traffic filtering solution
    icon
    Report and recommendations
    Test results summary and recommended actions to eliminate vulnerabilities
    Our approach

    To assess the security of the betting platform, we applied a black-box pentesting strategy along with both automated and manual testing of the web applications. We used OSINT techniques and tools such as Burp Suite, Nessus, and OWASP ZAP to identify both technical and logical vulnerabilities.

    Based on the penetration testing results, the Datami team compiled a report with findings and recommendations. To further enhance protection against DDoS attacks and bots, DataGuard and Cloudflare were implemented.

    Black-box
    Black-box
    Assessment from the perspective of an external attacker - without access to source code or internal information
    Key work stages and solutions

    After thorough preparation, the Datami team conducted full-scale black-box testing: they simulated potential attacks on the web applications and compiled a report on the discovered vulnerabilities.

    A separate stage involved implementing protective solutions, including the integration of DataGuard to defend against DDoS attacks and bots.

    • Preparation
      Analysis of testing objectives, development of attack scenarios, and selection of tools for black-box assessment.
       
    • Security assessment
      Automated and manual testing of two web applications (user/admin), attack simulation without access to source code.
       
    • Results & protection
      Risk evaluation, report preparation with technical details and recommendations. DataGuard implementation.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    During the testing of the betting platform, the Datami team discovered 30 vulnerabilities: 1 high, 7 medium, 19 low, and 3 informational. These affected both technical configurations and access to functionality in the user and admin areas.

    Based on the pentest results, we prepared a report and provided recommendations to enhance digital security:

    1. configure bot and DDoS protection using DataGuard and Cloudflare;
    2. fix incorrect access configurations;
    3. strengthen control over administrative privileges.

    Most vulnerabilities were addressed immediately, significantly increasing the platform’s overall security level.

    Our certificates
    Key project results

    Thanks to the project, 30 vulnerabilities were identified in the betting service, and protection against DDoS attacks was implemented using Dataguard and Cloudflare. As a result, the client achieved a significantly higher level of cybersecurity and platform stability.

    This case study highlights that even smaller market players can become targets for hackers. If your company handles payment information or processes personal data, security testing is essential.

    Category
    Before the project
    After implementation
    Security level
    Unknown, no independent assessment
    Real threat level identified: 30 vulnerabilities discovered
    Vulnerabilities
    Not identified
    Found: 1 high, 7 medium, 19 low, 3 informational
    DDoS protection
    Absent or unstable
    Dataguard and Cloudflare implemented
    Account compromise
    Risk for administrators
    Risk minimized through privilege restrictions
    Unauthorized access
    Potential threat
    Issues with access rights and configurations resolved
    More success stories with Datami
    Browse other project case studies
    DDoS Protection and 24/7 Cyber Monitoring

    DDoS Protection and 24/7 Cyber Monitoring

    • Implemented the DataGuard solution based on Cloudflare to protect the website
    • Established reliable protection against DDoS attacks and bot traffic
    Services:
    Implementation of DataGuard and Cloudflare, 24/7 monitoring
    Aug 8, 2025
    Website Protection from DDoS Attacks

    Website Protection from DDoS Attacks

    • Implemented the DataGuard solution for website protection
    • DDoS protection deployed within 3 days
    Services:
    Website protection with DataGuard (Cloudflare), continuous monitoring, Cloudflare infrastructure management
    Aug 8, 2025
    Protection of E-commerce Websites From DDoS via DataGuard

    Protection of E-commerce Websites From DDoS via DataGuard

    • Implemented DataGuard to protect from DDoS attacks
    • Enabled rapid incident response
    Services:
    24/7 cybersecurity monitoring, integration with Cloudflare
     
    Aug 7, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Pentesting Tools: Who and How Created Metasploit Datami Newsroom
    Datami Newsroom

    Pentesting Tools: Who and How Created Metasploit

    Metasploit is known for everyone interested in cybersecurity. It is not just a framework but a key driver of ethical hacking and pentesting, becoming the standard for thousands of professionals.

    Aug 26, 2025 3 min
    Fraudulent Applications in the Firefox Browser Datami Newsroom
    Datami Newsroom

    Fraudulent Applications in the Firefox Browser

    More than 40 fraudulent programs have been identified in the Mozilla Firefox browser. These extensions mimic legitimate wallet tools from popular platforms. The large-scale campaign has been ongoing since April 2025.

    Aug 22, 2025 3 min
    Large-Scale Fraudulent Operations on Android Datami Newsroom
    Datami Newsroom

    Large-Scale Fraudulent Operations on Android

    According to recent data, applications were discovered that loaded out-of-context ads onto users’ screens. The applications have already been removed by Google from the Play Store. The peak activity exceeded 1.2 billion requests per day.

    Aug 22, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy