Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
A poker program associated with loading a Magecart skimmer. This activity was discovered when a customer reported that they saw endpoint protection blocking network connections being made by their poker software. Further investigation led the researchers to discover that the malicious traffic occurring was an HTTP GET request to retrieve a JavaScript file. The JavaScript file contained the characteristics of a credit card skimmer and had the poker software’s website hardcoded into the script, indicating that it was custom designed to target that company. They discovered that the reason the poker software itself was loading this script was due to embedded browser pages within the application, not that the software was Trojanized. Visiting the website in a browser would lead to the skimmer being loaded also. The site was likely compromised by an exploit related to the vulnerable version of Drupal it was running. Enumerating other JavaScript files hosted on the remote domain used for the poker software skimmer, the researchers found several other skimmers designed to target specific companies’ websites.
Exposure of sensitive information
IP(s) / Hostname(s)
172[.]93[.]103[.]194
URLs