The challenge
ORADO's web platform and Android app are open to anyone on the internet and hold member and athlete data, registration records and tournament transactions. Both need independent testing in production without disrupting service during registration and tournament peaks.
EXECUTIVE SUMMARY
Federasi Olahraga Domino Nasional (ORADO) is the only official national governing body for the sport of domino in Indonesia. It organizes tournaments, manages athlete and club registration, and serves members and the public through a public web platform (orado.co.id) and a companion Android application — both openly accessible over the internet.
Zentara proposes a single WAPT engagement: grey-box penetration testing of the web platform, the Android application, and the API layer behind them, followed by a full remediation retest. Testing maps to the OWASP Top 10 (2025), OWASP Mobile Top 10 (2024), and OWASP API Security Top 10 (2023), and combines automated tooling with manual exploitation from senior operators.
Public-facing web and mobile applications are a primary target. In the 2025 Verizon DBIR, web applications were the vector in 42% of exploitation-based attacks, 88% of web-application breaches were powered by stolen credentials, and exploitation of vulnerabilities as an initial access route grew 34% year-over-year. For ORADO, member and athlete data, registration records, and tournament transactions are the assets at stake — and service continuity during registration and tournament peaks is an operational priority.
Because the engagement runs in production, high-risk tests are confined to agreed off-peak windows. Every finding is reproduced, CVSS v3.1 rated, and paired with remediation guidance; a knowledge-transfer session and a retest confirm closure. The result is objective evidence of independent testing under UU PDP No. 27/2022 and PP No. 71/2019.
2 Surfaces Web + Android mobile | Grey-Box Test approach | 3 Standards OWASP Web · Mobile · API | Retest Closure validated |
01 Client Profile & Platform Context
1.1 Client Profile
ORADO is the only official national governing body for the sport of domino in Indonesia. To organize tournaments, manage athlete and club registration, and serve its members and the public, ORADO operates a public-facing web platform (orado.co.id) and a companion Android application that are openly accessible to external users over the internet.
As public-facing assets, these applications are a primary target for cyberattacks. Weaknesses within them could expose member and athlete data, hijack accounts, deface services, or serve as a stepping stone into internal systems. Internal controls are already in place — this engagement provides the independent validation that proves whether they hold.
1.2 The Assets Under Test
The in-scope assets are ORADO’s web platform and Android application, plus the API layer behind them. The following profile was supplied by ORADO through the pre-engagement questionnaire.
Parameter | Response |
Object Under Test | Public web platform (orado.co.id) and Android mobile application |
Engagement Type | Web & Mobile Application Penetration Testing (WAPT) with Retest |
Methodology | Grey-Box |
Retest | Included — validation of all remediated findings |
Environment | Production (high-risk tests confined to agreed off-peak windows) |
Targets | 1 web platform, 1 mobile application (Android), plus API layer |
Reporting Standards | OWASP Top 10, OWASP Mobile Top 10, OWASP ASVS, OWASP WSTG, NIST SP 800-115, CVSS v3.1 |
Report Language | English |
Window | July 2026 — start W1, target completion W4 |
Why the assets matter. Every user credential, registration record, and tournament transaction is a valuable asset. A single flaw in a public web or mobile app can expose member and athlete data or interrupt service during the registration and tournament periods that matter most. |
02 The Challenge — Public Web & Mobile at Risk
Public web and mobile applications are where attackers concentrate. They expose business logic and data directly, and a single stolen credential often opens the door. The 2025 Verizon DBIR quantifies the pressure.
Metric | Value | Source |
Confirmed data breaches analyzed (2025) | 12,195 of 22,000+ incidents | Verizon DBIR 2025 |
Exploitation of vulnerabilities as initial access | 20% of breaches (+34% YoY) | Verizon DBIR 2025 |
Exploitation attacks whose vector was a web application | 42% | Verizon DBIR 2025 (Edgescan) |
Web-application breaches powered by stolen credentials | 88% | Verizon DBIR 2025 (Edgescan) |
Credential abuse as an initial attack vector | 22% | Verizon DBIR 2025 |
Third-party involvement in breaches | 30% (doubled YoY) | Verizon DBIR 2025 |
Ransomware presence in breaches | 44% (+37% YoY) | Verizon DBIR 2025 |
Median time to fix a web-app vulnerability | 74.3 days (vs 54.8 network) | Verizon DBIR 2025 (Edgescan) |
The Android application widens the surface further — insecure storage, weak binary protections, and unvalidated communication add mobile-specific risk on top of the shared backend and API layer. ORADO’s estate therefore needs authentication, authorization, session management, business logic, and API-layer testing across both web and mobile.
Public-facing means externally exposed. Both applications answer to anyone with an internet connection, so the attack surface reaches beyond ORADO’s network. Testing runs in production — which is where the real risk lives — with high-risk scenarios confined to agreed off-peak windows to protect continuity. |
03 Problem Identification — Attack Surface & Test Hypotheses
The pre-engagement data maps to a set of concrete risk hypotheses. Each becomes a test case with a pass/fail verdict backed by reproducible evidence.
Risk Hypothesis | What Zentara Validates |
Public web exposure | Enumeration of the orado.co.id surface, hidden endpoints, and exposed admin or config |
Authentication & session | Credential-stuffing resistance, session handling, MFA gaps, and account-takeover paths |
Broken access control | IDOR and privilege escalation across member, athlete, and tournament records |
Injection & input handling | SQL / NoSQL, command, and cross-site scripting across registration and tournament inputs |
Business-logic abuse | Registration and tournament workflow bypass and manipulation |
API layer (REST / GraphQL / SOAP) | Authorization, rate limiting, and data exposure at the API tier |
Mobile app (Android) | Insecure storage, weak binary protections, insecure communication, and backend trust |
Availability during peaks | Safe testing in production within agreed off-peak windows |
From questionnaire to evidence. Each hypothesis becomes a documented test with a verdict and reproducible proof — replacing open questions about ORADO’s posture with measured facts. |
04 The Zentara Solution — Three Pillars
Zentara delivers this as one engagement combining an offensive testing program across the web and mobile estate with a structured remediation and retest cycle. Each finding is supported by evidence and a validated fix, so every issue raised gets a concrete answer.
Pillar | Focus |
1 · Web Application Penetration Testing | Grey-box testing of the orado.co.id platform aligned with the OWASP Top 10 (2025), ASVS, and WSTG — covering authentication, authorization, session management, injection, and business-logic testing, plus API-layer endpoints (REST, GraphQL, SOAP) against the OWASP API Security Top 10 (2023). |
2 · Mobile Application Penetration Testing | Grey-box testing of the Android application aligned with the OWASP Mobile Top 10 (2024) — static (SAST) and dynamic (DAST) analysis, reverse engineering, and code-tampering testing. |
3 · Remediation, Retest & Knowledge Transfer | Prioritized technical remediation guidance, a knowledge-transfer session with the ORADO IT team, and a retest that validates the effectiveness of every fix. |
Measurable remediation, not just a list. Every finding closes the loop — reproduce, rate, remediate, retest. Zentara re-tests each fixed issue and records the outcome in a retest report before the engagement ends. |
05 Testing Methodology — WAPT (Grey-Box)
The engagement follows Zentara’s VAPT methodology: a hybrid of automated tooling for coverage and manual exploitation for depth, executed by senior operators and governed by rules of engagement and an NDA. Reporting is dual-layer — an executive summary and a detailed technical report.
Phase | Focus | Key Output |
1 Scoping & RoE | Confirm scope, off-peak windows, escalation, and legal authorization; sign the NDA | Signed RoE & NDA |
2 Reconnaissance | Surface mapping, endpoint and API enumeration across web and mobile | Attack-surface map |
3 Web & API Testing | Grey-box exploitation — access control, auth, session, injection, business logic, API tier | Proven web / API findings |
4 Mobile Testing | Android SAST + DAST, reverse engineering, and code-tampering testing | Proven mobile findings |
5 Reporting | Executive summary plus technical report with severity matrix, CVSS v3.1, and PoC | WAPT report (dual-layer) |
6 Remediation & Retest | Knowledge-transfer session, retest of each fix, and a consolidated final report | Closure validation |
STANDARDS: OWASP Top 10 (2025) · OWASP Mobile Top 10 (2024) · OWASP API Security Top 10 (2023) · OWASP ASVS · OWASP WSTG · NIST SP 800-115 · CVSS v3.1
Hybrid, by senior operators. Automated tooling gives coverage; senior pentesters (OSCP, eWPT, eWPTX, CEH) give depth — both the web and the mobile assessment are run by senior operators. Every reported finding is manually validated. |
06 OWASP Coverage — Web (2025) & Mobile (2024)
6.1 OWASP Top 10 (2025) — Web Platform (orado.co.id)
ID | Risk | What Zentara Tests |
A01:2025 | Broken Access Control | IDOR and privilege escalation on member, athlete, and tournament records; forced browsing |
A02:2025 | Security Misconfiguration | Headers, TLS, CORS, verbose errors, default configs, and exposed admin panels |
A03:2025 | Software Supply Chain Failures | Vulnerable / outdated components and third-party script integrity |
A04:2025 | Cryptographic Failures | TLS strength, sensitive data in transit and at rest, token and password storage |
A05:2025 | Injection | SQL / NoSQL, command, and XSS across registration and tournament inputs |
A06:2025 | Insecure Design | Business-logic abuse — registration and tournament workflow bypass |
A07:2025 | Authentication Failures | Credential stuffing, weak session management, MFA gaps, account takeover |
A08:2025 | Software or Data Integrity Failures | Unverified updates, deserialization, and integrity of critical data flows |
A09:2025 | Security Logging & Alerting Failures | Detection gaps for authentication abuse and high-risk actions |
A10:2025 | Mishandling of Exceptional Conditions | Error and edge-case handling, fail-open logic, and information leakage |
6.2 OWASP Mobile Top 10 (2024) — Android Application
ID | Risk | What Zentara Tests |
M1 | Improper Credential Usage | Hardcoded or insecurely stored credentials and tokens in the app |
M2 | Inadequate Supply Chain Security | Vulnerable third-party SDKs and libraries |
M3 | Insecure Authentication / Authorization | Session and authorization handling between the app and backend |
M4 | Insufficient Input / Output Validation | Injection and data manipulation via app inputs and API calls |
M5 | Insecure Communication | TLS validation, certificate pinning, and data in transit |
M6 | Inadequate Privacy Controls | Excessive data collection and handling of personal data |
M7 | Insufficient Binary Protections | Reverse-engineering and code-tampering resistance |
M8 | Security Misconfiguration | Debuggable builds, excessive permissions, and exported components |
M9 | Insecure Data Storage | Sensitive data stored unencrypted on the device |
M10 | Insufficient Cryptography | Weak algorithms and key management |
Access control and authentication lead. Broken access control (A01) and authentication failures (A07) top the web risks, and improper credentials (M1) top the mobile list. The grey-box design puts the heaviest manual effort exactly there. |
07 Scope of Work
7.1 Assessment Types
☑ Web Application Security Assessment
☑ Mobile Application Security Assessment (Android)
☐ API & Web Services Security Assessment (covered within the web engagement)
☐ ISO 27001:2022 ISMS Assessment
☐ External / Internal Network Infrastructure Assessment
7.2 Approach
☐ Black-Box — no prior information provided
☑ Grey-Box — the testing team is given limited knowledge or user-level credentials
☐ White-Box — full system detail, including source code and administrative access
7.3 Assets In-Scope
Testing is authorized only for the assets agreed and listed below.
Asset (Type / Application) | Service | Environment |
ORADO Web Platform (orado.co.id) | WAPT — Web | Production |
ORADO Mobile Application (Android) | WAPT — Mobile | Production |
7.4 Assets Out-of-Scope & Limitations
Any asset not explicitly listed as in-scope is out-of-scope. The following are strictly prohibited:
— Denial of Service (DoS / DDoS), automated brute-force without rate limits, and destructive exploitation affecting live database integrity.
— Social engineering of any form — phishing, smishing, or vishing against employees.
— Testing against any system, application, network, or infrastructure not on the approved target list.
— High-risk scenarios outside agreed off-peak hours.
Authorization boundary. Zentara will not test any asset outside the in-scope list without written approval. All activity follows OWASP best practice and is conducted with care for the stability of production services. |
08 Compliance & Regulatory Alignment
The engagement produces evidence of independent security testing — supporting ORADO’s obligations under Indonesian law and its accountability to members, partners, and regulators.
Regulation / Standard | Relevance to This Engagement |
UU No. 27/2022 — Personal Data Protection (PDP) | Independent testing supports accountability for protecting member and athlete data. Administrative fines reach 2% of annual revenue; criminal fines of Rp4–6 billion and 4–6 years apply to unlawful data handling. |
PP No. 71/2019 — Electronic Systems & Transactions (PSTE) | Electronic system operators must guarantee the security and reliability of their systems and protect personal data. A WAPT evidences that duty of care. |
OWASP & NIST SP 800-115 | Industry-standard testing coverage — OWASP Top 10, Mobile Top 10, ASVS, and WSTG under the NIST SP 800-115 methodology — demonstrating due diligence. |
Testing as evidence. A validated WAPT report — with a retest confirming closure — is objective proof to members, regulators, and leadership that ORADO’s public applications were independently assessed against recognized standards. |
09 Deliverables
ORADO receives a complete, actionable package — built for both leadership and engineering.
— Executive Summary Report — risk posture and business impact for leadership.
— Detailed Technical Report — a Vulnerability Severity Matrix, proof-of-concept evidence, and remediation recommendations, each finding CVSS v3.1 rated.
— Retest Report — validating remediation of each finding.
— Final Report — consolidating the assessment and post-remediation status.
— Knowledge-transfer session — with the ORADO IT team.
4 Reports Exec · Technical · Retest · Final | CVSS v3.1 Severity matrix | PoC Evidence per finding | Retest Closure validated |
10 Delivery Timeline & Team
The engagement is scheduled across a July 2026 window. Web and mobile testing are both delivered by senior pentesters; detailed scheduling is confirmed at kick-off.
Stage | Window (July 2026) | Focus |
Kick-off & Scoping | Week 1 | RoE, NDA, off-peak windows, and target confirmation |
Web + Mobile Testing | Early July | Grey-box web, Android, and API-layer testing |
Reporting | Week 2 | Executive + technical report, CVSS v3.1, severity matrix |
Remediation (ORADO) | Mid-July | ORADO applies fixes with Zentara advisory |
Retest & Final Report | End July | Per-finding closure validation and consolidated final report |
Role | Responsibility | Certifications |
Project Manager | Single point of contact; planning, scheduling, scope and quality control; NDA and Rules of Engagement; reporting and acceptance | PM · GRC |
Senior Pentester — Web | Grey-box web and API-layer testing; manual exploitation; PoC evidence; retest | OSCP, eWPT, eWPTX, CEH |
Senior Pentester — Mobile | Android SAST / DAST, reverse engineering, and code-tampering; PoC evidence; retest | OSCP, eWPT, CEH |
Senior operators, production-safe. Both the web and mobile assessments are executed by senior pentesters under a defined methodology and quality-review process — with a proven track record of assessing live production environments without service disruption. |
Outcome & next steps
Outcome & next steps
Delivered in July 2026: grey-box testing of the web platform, Android app and API layer against the OWASP Top 10 (2025), Mobile Top 10 (2024) and API Security Top 10 (2023); executive, technical, retest and final reports, with every finding reproduced, CVSS v3.1 rated and paired with remediation guidance; a knowledge-transfer session with ORADO's IT team; and a retest validating each remediated finding.
