Dunicot A cybersecurity consultancy and advisory firm.

Case studies · Four engagements

What the work looks like.

Four engagements, described the way they ran: what was scoped, how it was approached, what classes of finding came out, and what changed afterwards. Clients are named only where the work is already public, and findings are described by class rather than by reproduction detail.

Attack scenarios

Alongside the engagements above we publish a page per vulnerability class: how the attack unfolds, what it costs, how a tester confirms it and the control that holds.

Critical · E-commerce and retail

SQL injection in e-commerce

SQL injection, or SQLi, can turn one unparameterised product filter into a read of every customer name, address, order and password hash. How to test for it.

High to Critical · Healthcare

Stored XSS account takeover

Stored XSS: text saved in a patient message field runs inside the clinician console, drives the staff session and reads every record that account can reach.

Critical · Insurance

Server-side request forgery

Server-side request forgery (SSRF) can turn a URL field into theft of a server's cloud credentials, and then every file in storage. How we test for it.

High to Critical · HR and payroll software

GraphQL introspection and batching

Introspection maps the GraphQL schema, a missing field authorisation check opens the records, and alias batching reads thousands of them in one POST.

Critical · Travel and hospitality

OAuth account takeover

A loose redirect_uri check leaks an OAuth code, letting an attacker take over an SSO account and reach the loyalty balance and passport data inside it.

Critical · Manufacturing

Kerberoasting to Domain Admin

Kerberoasting lets any authenticated domain user crack a service account password offline and reach Domain Admin, with no failed logons and no lockouts.

Critical (conditional) · Government and public sector

Dependency confusion

Dependency confusion lets an attacker register your internal package name on npm or PyPI, so the next build installs theirs and runs it on the build agent.

View all attack scenarios

Wider sample

A non-exhaustive list of delivered engagement types, described by sector and scope.

Selected engagements by sector
SectorScopeOutcome
BankingInternet banking web apps, banking APIs, Android app, ATM & CDM, servers and networkFull VAPT with R&D phase and consolidated reporting
AviationGlobal private-jet charter booking platformVulnerability assessment across the booking and account surface
Logistics · UAELuggage pickup and airport drop platformCustomer information exposure identified and remediated
SaaSInternal workforce management applicationCritical authentication bypass and access-control flaws
Mobile · SASTConsumer mobile application source codeManual static review with source-aware remediation guidance
WebConsumer web platformAuthentication, authorisation and user-data protection assessment
InsuranceInsurer digital forensics engagementDisk imaging, registry analysis and deleted-file recovery
Fintech · KSAPayments platform, API and infrastructureEnd-to-end VAPT engagement

Want the full sample report?

A redacted sample report showing the structure, the severity language and the evidence format is available on request under NDA.