A Sintropyc proof report, start to finish.
This is the exact deliverable you receive after a run: every finding proven by a working exploit, with the impact, the precise fix and a retest verdict. It reads for both the engineer who fixes it and the stakeholder who signs off.
acme-shop — storefront SaaS: web & API security assessment
Executive summary
An autonomous agent tested acme-shop the way a real attacker would, starting black-box from the URL. It found that the API did not enforce object-level authorization: one registered customer could read another owner's private profile by changing a single integer, and could escalate itself to admin by setting a client-supplied role field. To prove the escalation was real, it used the privilege — opening the private admin revenue dashboard as a customer registered sixty seconds earlier.
Every finding here is demonstrated by effect, not asserted from a signature. Where the first authorization signal could have been a shared-workspace feature rather than a bug, the agent rejected its own finding and re-proved it against genuinely separate owners. Severity is set to exactly what was shown — never higher.
Two critical authorization flaws chain into full account and store takeover. Both are server-side authorization gaps with unglamorous, well-understood fixes. All are fixable without a redesign; the retest section shows each one closed.
Findings
- Class
- IDOR / BOLA · CWE-639
- Endpoint
GET /api/members/{id}- Auth
- Any registered customer
- Status
- Proven by effect
Member IDs are sequential integers and the member object carries a password-recovery hint — a private field that should never leave the owner's own session. As Account A, the agent requested member records it did not own and received full profiles, recovery-hint included.
Exploitation capture redacted in this public sample. Your report includes the annotated request/response and screenshot.
Any customer can harvest every other member's email, name and recovery hint by walking the ID range — a mass privacy breach and the raw material for targeted account takeover.
Authorize every object access server-side, default-deny: on each /{id} route verify the caller may see that specific object. Never expose recovery hints through a profile read.
403 Forbidden; own record still returns 200.- Class
- Mass assignment · CWE-915
- Endpoint
POST /api/register,PATCH /api/members/{id}- Auth
- Unauthenticated → self-elevated
- Status
- Proven by effect
The registration and profile-update endpoints accept a client-supplied role field and persist it as-is. The agent registered a fresh customer with role: admin and then used the privilege — opening the private admin dashboard (total members and revenue) with a 200 OK.
Exploitation capture redacted in this public sample. Your report includes the annotated capture of the admin dashboard.
Anyone who can register can become an administrator and read or change all store data — full store takeover. The same field on the update path let one customer flip another customer's role.
Allow-list writable fields on every input binding; set role, tier and owner server-side through admin-only paths, never from the request body.
role and defaults to customer; the admin dashboard returns 403 to non-admins.alg:none JWT accepted- Class
- Broken access control · CWE-287 / CWE-347
- Endpoint
GET /admin/*,GET /api/users- Auth
- None required
- Status
- Proven by effect
Several /admin/* routes and a user-listing endpoint returned data to a completely unauthenticated request — store configuration, the revenue dashboard, and every member's email and full name. The server also accepted JWTs with alg: none and honoured forged claims.
The full member directory is exposed with no authentication, and the alg:none flaw lets an attacker mint any identity. Where a signing secret could not be observed, that part is marked inferred, not proven.
Require authentication and authorization on every /admin and /internal route (assume public until proven otherwise). Reject alg:none, pin the algorithm, verify signatures, and rotate any leaked secret.
/api/users now require an authorized session; unsigned tokens are rejected with 401.- Class
- Security misconfiguration · CWE-693
- Endpoint
- Global responses
- Auth
- n/a
- Status
- Observed
Responses omit Content-Security-Policy and Strict-Transport-Security, and the session cookie is set without Secure / SameSite. Not directly exploited here, but each widens the blast radius of any client-side bug.
Add a restrictive CSP and HSTS; set session cookies HttpOnly; Secure; SameSite=Lax.
- Class
- Information exposure · CWE-209
- Endpoint
POST /api/checkout(malformed body)- Auth
- Any customer
- Status
- Observed
A malformed request returns a framework stack trace disclosing the ORM, library versions and internal file paths — useful reconnaissance for an attacker, not a breach on its own.
Return generic error bodies in production; log details server-side only.
400 body; no trace disclosed.Static-analysis appendix
Where source or a mirror is available, the report includes a short static pass alongside the proven findings — the classes above traced back to the code paths that produce them, plus any secrets or risky patterns spotted in the tree. It complements the exploit proof; it never replaces it.
Verdict & methodology
acme-shop shipped two critical, chainable authorization flaws — but every one has a clear, server-side fix, and the retest confirms all five findings closed. That is the shape of a Sintropyc report: proof, not guess, a precise fix for each finding, and a second attack to prove the fix held.
- Authorized & scoped — run only against the target you own or are authorised to test.
- Read-only by default — the smallest safe effect proves each finding; writes need an explicit flag and reverse cleanly.
- Data boundary — your real data and secrets never reach the AI model; testing uses fictional accounts.
- Human-reviewed — a person checks every finding before the report reaches you.
See the same engagement told as a narrative in the IDOR → account-takeover case study, or exactly what a run needs and how long it takes in How it works.