Vistra is a global service provider offering fund administration and corporate services. It supports business growth by helping with hiring, market expansion, productivity improvement, and operational structuring.
Corporate Services and Fund Administration
Web Application Penetration Testing
Financial Services
Vistra’s web application, used to manage governance, risk, compliance, advisory, finance, and administrative activities, was experiencing frequent functional and security problems affecting smooth service delivery.
Planned and conducted vulnerability assessment and penetration testing
Gathered information to identify operational and security issues
Executed in-depth penetration testing to assess vulnerability impact
Suggested remediation based on identified vulnerabilities
Discovered issues such as Cross Site Scripting (Stored and Reflected), Business Logic Abuse, Authentication Bypass, and Formula Injection impacting critical operations.
Identified deprecated TLS, missing security headers, information disclosure, and cookie security weaknesses requiring remediation.
Our team used standard testing methodologies including OWASP, NIST, PTES, and OSSTMM, and tools such as Nessus, Burp Suite, nMap, Wireshark, BeEF, and SQL Ninja. We mapped threats, analysed each vulnerability’s impact, and provided actionable recommendations.
Identified multiple vulnerabilities posing significant security risks
Reviewed and improved internal security policies and controls, including error-handling documentation
Recommended a comprehensive security plan to meet compliance requirements and secure the application