Research Library / Case Studies /

Digital Transformation, Security & Protection

Security Assessment of an International Event's Android Application

An International Event’s Android Application Was Assessed To Identify Any Threats And Security- Related Issues. This Case Study Will You A Glimpse Of How Payatu Assessed The Android App.
Mobile (Android) Security Assessment, Black-Box Penetration Testing

At a glance

INDUSTRY

Digital Transformation, Security & Protection

CLIENT PROFILE

A digital transformation organization building the official app for a major international event

SERVICES

Mobile (Android) Security Assessment, Black-Box Penetration Testing

ENGAGEMENT

Pre-launch Android app security assessment

Key Takeaways

  • Client – A digital transformation organization building the Android app for a six-month international event held on a truly global stage.

  • Problem – The app needed to be tested for vulnerabilities that could lead to a major data leak, loss of goodwill, or reputational damage before it reached a global audience.

  • What Payatu did – Payatu Bandits ran black-box static and dynamic testing of the Android app, mapping findings to the OWASP Mobile Top 10, including login bypass attempts with tools like Drozer.

  • Outcome – Payatu delivered findings and remediation steps covering database hardening, server and authentication configuration, and third- party module updates ahead of the event.

the challenge

Why the client called us in

The client, a digital transformation organization based in the UAE, was building the Android app for a distinguished international event running six months and drawing 192 participating nations. Any anomaly in the app risked a major data leak, loss of goodwill, and reputational damage at a global scale, so the client needed the app tested and hardened before it reached that audience. It brought in Payatu to simulate real-world attackers against the app and its guest functionality.

  • Identify and exploit vulnerabilities in the Android app before launch
  • Test the app's guest functionality under real-world attack conditions
  • Get clear, actionable remediation steps ahead of the event

‍
‍

scope of engagement

What was in scope

  1. Comprehensive analysis of the Android mobile application
  2. Android mobile application testing
  3. Black-box testing
  4. Testing the guest functionality
  5. Reporting in the client's required format

Our Approach

How Payatu ran the engagement

01

Static testing
Payatu decompiled the application, searched for hardcoded secrets and sensitive information, tested login bypass on the app's components using tools such as Drozer, and followed the OWASP Android checklist.

02

Dynamic testing
The team used Burp Suite's active scanner alongside manual test cases, attempted malicious file uploads, tried transferring notifications meant for one user to another, and followed the OWASP web checklist.

03

Reporting
Payatu mapped every finding to the OWASP Mobile Top 10 and delivered a report in the client's required format.

Key findings

What we found

Access & Authentication
Testing surfaced authentication-related issues, including paths to bypass the login mechanism using tools like Drozer.
Data & Database Exposure
Payatu found access to the underlying database structure, creating a risk of a major data leak if left unaddressed.
Server Configuration
The assessment identified a misconfigured server, adding to the app's exposure ahead of a global-scale launch.

the outcome

Results and Impact

Working against the scale of an app meant to serve visitors from 192 nations, Payatu identified the vulnerabilities that mattered most, from database exposure to authentication weaknesses to server misconfiguration, and handed the client clear steps to close them before the event went live.

‍

  • Tested the app's guest functionality against real-world attack scenarios

  • Mapped every finding to the OWASP Mobile Top 10

  • Flagged database exposure, server misconfiguration, and authentication issues

  • Delivered hardening recommendations for the database, server, and authentication flow

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment