Sample report

A Sintropyc proof report, start to finish.

By Sintropyc · Sample deliverable

This is the exact deliverable you receive after a run: every finding proven by a working exploit, with the impact, the precise fix and a retest verdict. It reads for both the engineer who fixes it and the stakeholder who signs off.

Run a scan on your appHow it works →
Sample
Anonymized example on a fictional target. The findings below are drawn from a real, authorized engagement but the target, domain, users and secrets are fictional or redacted — nothing here identifies a real system. Your report follows this same structure.
Proof report · v1

acme-shop — storefront SaaS: web & API security assessment

Target
acme-shop (fictional)
Engagement
Proof scan — one run
Surface
Web app · JSON API · auth layer
Method
Authorized · read-only default
Report ID
SAMPLE-0001
Retest
Included after fix
2 Critical 1 High 1 Medium 1 Low

Executive summary

An autonomous agent tested acme-shop the way a real attacker would, starting black-box from the URL. It found that the API did not enforce object-level authorization: one registered customer could read another owner's private profile by changing a single integer, and could escalate itself to admin by setting a client-supplied role field. To prove the escalation was real, it used the privilege — opening the private admin revenue dashboard as a customer registered sixty seconds earlier.

Every finding here is demonstrated by effect, not asserted from a signature. Where the first authorization signal could have been a shared-workspace feature rather than a bug, the agent rejected its own finding and re-proved it against genuinely separate owners. Severity is set to exactly what was shown — never higher.

Bottom line

Two critical authorization flaws chain into full account and store takeover. Both are server-side authorization gaps with unglamorous, well-understood fixes. All are fixable without a redesign; the retest section shows each one closed.

Findings

FINDING 01
Broken object-level authorization → cross-account data disclosure
Critical
Class
IDOR / BOLA · CWE-639
Endpoint
GET /api/members/{id}
Auth
Any registered customer
Status
Proven by effect

Member IDs are sequential integers and the member object carries a password-recovery hint — a private field that should never leave the owner's own session. As Account A, the agent requested member records it did not own and received full profiles, recovery-hint included.

Evidence
# As Account A (id 2087), request a foreign member GET /api/members/1042 HTTP/1.1 Host: app.acme-shop.example Authorization: Bearer <account-A session> HTTP/1.1 200 OK { "id": 1042, "email": "j••••@••••.example", "recovery_hint": "••••••", ← private, foreign owner "role": "customer" }
Proof
proof · foreign profile returned to Account A
🔒

Exploitation capture redacted in this public sample. Your report includes the annotated request/response and screenshot.

Impact

Any customer can harvest every other member's email, name and recovery hint by walking the ID range — a mass privacy breach and the raw material for targeted account takeover.

Remediation

Authorize every object access server-side, default-deny: on each /{id} route verify the caller may see that specific object. Never expose recovery hints through a profile read.

✓
Retest — fixed. After the fix, Account A requesting a foreign member returns 403 Forbidden; own record still returns 200.
FINDING 02
Mass assignment on registration → privilege escalation to admin
Critical
Class
Mass assignment · CWE-915
Endpoint
POST /api/register, PATCH /api/members/{id}
Auth
Unauthenticated → self-elevated
Status
Proven by effect

The registration and profile-update endpoints accept a client-supplied role field and persist it as-is. The agent registered a fresh customer with role: admin and then used the privilege — opening the private admin dashboard (total members and revenue) with a 200 OK.

Evidence
# Register, smuggling a privileged field POST /api/register HTTP/1.1 { "email":"a•••@••••.example", "password":"•••", "role":"admin" } HTTP/1.1 201 Created ← role accepted verbatim # Use it: read the private admin dashboard GET /admin/dashboard HTTP/1.1 Authorization: Bearer <new customer session> HTTP/1.1 200 OK { "members": 48213, "revenue_usd": "•••••" }
Proof
proof · admin dashboard opened as new customer
🔒

Exploitation capture redacted in this public sample. Your report includes the annotated capture of the admin dashboard.

Impact

Anyone who can register can become an administrator and read or change all store data — full store takeover. The same field on the update path let one customer flip another customer's role.

Remediation

Allow-list writable fields on every input binding; set role, tier and owner server-side through admin-only paths, never from the request body.

✓
Retest — fixed. Registration now ignores role and defaults to customer; the admin dashboard returns 403 to non-admins.
FINDING 03
Unauthenticated admin endpoints & alg:none JWT accepted
High
Class
Broken access control · CWE-287 / CWE-347
Endpoint
GET /admin/*, GET /api/users
Auth
None required
Status
Proven by effect

Several /admin/* routes and a user-listing endpoint returned data to a completely unauthenticated request — store configuration, the revenue dashboard, and every member's email and full name. The server also accepted JWTs with alg: none and honoured forged claims.

Evidence
# No token, no session — just a GET GET /api/users HTTP/1.1 Host: app.acme-shop.example HTTP/1.1 200 OK [ { "email":"•••@•••", "name":"••• •••" }, … 48k rows ] # Forged unsigned token is honoured Authorization: Bearer eyJhbGciOiJub25lIn0.<forged claims>. HTTP/1.1 200 OK
Impact

The full member directory is exposed with no authentication, and the alg:none flaw lets an attacker mint any identity. Where a signing secret could not be observed, that part is marked inferred, not proven.

Remediation

Require authentication and authorization on every /admin and /internal route (assume public until proven otherwise). Reject alg:none, pin the algorithm, verify signatures, and rotate any leaked secret.

✓
Retest — fixed. Admin routes and /api/users now require an authorized session; unsigned tokens are rejected with 401.
FINDING 04
Security headers & cookie flags incomplete
Medium
Class
Security misconfiguration · CWE-693
Endpoint
Global responses
Auth
n/a
Status
Observed

Responses omit Content-Security-Policy and Strict-Transport-Security, and the session cookie is set without Secure / SameSite. Not directly exploited here, but each widens the blast radius of any client-side bug.

Remediation

Add a restrictive CSP and HSTS; set session cookies HttpOnly; Secure; SameSite=Lax.

✓
Retest — fixed. Headers present; cookie flags set.
FINDING 05
Verbose error responses leak stack traces
Low
Class
Information exposure · CWE-209
Endpoint
POST /api/checkout (malformed body)
Auth
Any customer
Status
Observed

A malformed request returns a framework stack trace disclosing the ORM, library versions and internal file paths — useful reconnaissance for an attacker, not a breach on its own.

Remediation

Return generic error bodies in production; log details server-side only.

✓
Retest — fixed. Generic 400 body; no trace disclosed.

Static-analysis appendix

Where source or a mirror is available, the report includes a short static pass alongside the proven findings — the classes above traced back to the code paths that produce them, plus any secrets or risky patterns spotted in the tree. It complements the exploit proof; it never replaces it.

Verdict & methodology

acme-shop shipped two critical, chainable authorization flaws — but every one has a clear, server-side fix, and the retest confirms all five findings closed. That is the shape of a Sintropyc report: proof, not guess, a precise fix for each finding, and a second attack to prove the fix held.

Read next

See the same engagement told as a narrative in the IDOR → account-takeover case study, or exactly what a run needs and how long it takes in How it works.

Get this report for your own app

One fixed price. A full test, every finding proven with a working exploit, the exact fix, and a retest after you ship.