ZENTARA
← All impact studies
Offensive security/ Sports governing body

Web and Mobile Penetration Testing for ORADO

A grey-box penetration test with retest of ORADO's public web platform, Android app and the API layer behind them, run in production without disrupting registration and tournament activity.

ORADO (Federasi Olahraga Domino Nasional)Completed engagement
ORADO
Illustrative imagery

Completed engagement, delivered in July 2026. Specific findings are not published. Industry statistics are cited from the Verizon DBIR 2025.

Scope
2 surfaces
Web and Android
Plus the API layer
Scope
Grey-box
Test approach
User-level access
Scope
3 OWASP lists
Web, mobile and API
2025, 2024 and 2023 editions
Scope
4 reports
Executive, technical, retest, final
Every finding CVSS v3.1 rated

The challenge

ORADO's web platform and Android app are open to anyone on the internet and hold member and athlete data, registration records and tournament transactions. Both need independent testing in production without disrupting service during registration and tournament peaks.

EXECUTIVE SUMMARY

Federasi Olahraga Domino Nasional (ORADO) is the only official national governing body for the sport of domino in Indonesia. It organizes tournaments, manages athlete and club registration, and serves members and the public through a public web platform (orado.co.id) and a companion Android application — both openly accessible over the internet.

Zentara proposes a single WAPT engagement: grey-box penetration testing of the web platform, the Android application, and the API layer behind them, followed by a full remediation retest. Testing maps to the OWASP Top 10 (2025), OWASP Mobile Top 10 (2024), and OWASP API Security Top 10 (2023), and combines automated tooling with manual exploitation from senior operators.

Public-facing web and mobile applications are a primary target. In the 2025 Verizon DBIR, web applications were the vector in 42% of exploitation-based attacks, 88% of web-application breaches were powered by stolen credentials, and exploitation of vulnerabilities as an initial access route grew 34% year-over-year. For ORADO, member and athlete data, registration records, and tournament transactions are the assets at stake — and service continuity during registration and tournament peaks is an operational priority.

Because the engagement runs in production, high-risk tests are confined to agreed off-peak windows. Every finding is reproduced, CVSS v3.1 rated, and paired with remediation guidance; a knowledge-transfer session and a retest confirm closure. The result is objective evidence of independent testing under UU PDP No. 27/2022 and PP No. 71/2019.

2 Surfaces

Web + Android mobile

Grey-Box

Test approach

3 Standards

OWASP Web · Mobile · API

Retest

Closure validated

01 Client Profile & Platform Context

1.1 Client Profile

ORADO is the only official national governing body for the sport of domino in Indonesia. To organize tournaments, manage athlete and club registration, and serve its members and the public, ORADO operates a public-facing web platform (orado.co.id) and a companion Android application that are openly accessible to external users over the internet.

As public-facing assets, these applications are a primary target for cyberattacks. Weaknesses within them could expose member and athlete data, hijack accounts, deface services, or serve as a stepping stone into internal systems. Internal controls are already in place — this engagement provides the independent validation that proves whether they hold.

1.2 The Assets Under Test

The in-scope assets are ORADO’s web platform and Android application, plus the API layer behind them. The following profile was supplied by ORADO through the pre-engagement questionnaire.

Parameter

Response

Object Under Test

Public web platform (orado.co.id) and Android mobile application

Engagement Type

Web & Mobile Application Penetration Testing (WAPT) with Retest

Methodology

Grey-Box

Retest

Included — validation of all remediated findings

Environment

Production (high-risk tests confined to agreed off-peak windows)

Targets

1 web platform, 1 mobile application (Android), plus API layer

Reporting Standards

OWASP Top 10, OWASP Mobile Top 10, OWASP ASVS, OWASP WSTG, NIST SP 800-115, CVSS v3.1

Report Language

English

Window

July 2026 — start W1, target completion W4

Why the assets matter. Every user credential, registration record, and tournament transaction is a valuable asset. A single flaw in a public web or mobile app can expose member and athlete data or interrupt service during the registration and tournament periods that matter most.

02 The Challenge — Public Web & Mobile at Risk

Public web and mobile applications are where attackers concentrate. They expose business logic and data directly, and a single stolen credential often opens the door. The 2025 Verizon DBIR quantifies the pressure.

Metric

Value

Source

Confirmed data breaches analyzed (2025)

12,195 of 22,000+ incidents

Verizon DBIR 2025

Exploitation of vulnerabilities as initial access

20% of breaches (+34% YoY)

Verizon DBIR 2025

Exploitation attacks whose vector was a web application

42%

Verizon DBIR 2025 (Edgescan)

Web-application breaches powered by stolen credentials

88%

Verizon DBIR 2025 (Edgescan)

Credential abuse as an initial attack vector

22%

Verizon DBIR 2025

Third-party involvement in breaches

30% (doubled YoY)

Verizon DBIR 2025

Ransomware presence in breaches

44% (+37% YoY)

Verizon DBIR 2025

Median time to fix a web-app vulnerability

74.3 days (vs 54.8 network)

Verizon DBIR 2025 (Edgescan)

The Android application widens the surface further — insecure storage, weak binary protections, and unvalidated communication add mobile-specific risk on top of the shared backend and API layer. ORADO’s estate therefore needs authentication, authorization, session management, business logic, and API-layer testing across both web and mobile.

Public-facing means externally exposed. Both applications answer to anyone with an internet connection, so the attack surface reaches beyond ORADO’s network. Testing runs in production — which is where the real risk lives — with high-risk scenarios confined to agreed off-peak windows to protect continuity.

03 Problem Identification — Attack Surface & Test Hypotheses

The pre-engagement data maps to a set of concrete risk hypotheses. Each becomes a test case with a pass/fail verdict backed by reproducible evidence.

Risk Hypothesis

What Zentara Validates

Public web exposure

Enumeration of the orado.co.id surface, hidden endpoints, and exposed admin or config

Authentication & session

Credential-stuffing resistance, session handling, MFA gaps, and account-takeover paths

Broken access control

IDOR and privilege escalation across member, athlete, and tournament records

Injection & input handling

SQL / NoSQL, command, and cross-site scripting across registration and tournament inputs

Business-logic abuse

Registration and tournament workflow bypass and manipulation

API layer (REST / GraphQL / SOAP)

Authorization, rate limiting, and data exposure at the API tier

Mobile app (Android)

Insecure storage, weak binary protections, insecure communication, and backend trust

Availability during peaks

Safe testing in production within agreed off-peak windows

From questionnaire to evidence. Each hypothesis becomes a documented test with a verdict and reproducible proof — replacing open questions about ORADO’s posture with measured facts.

04 The Zentara Solution — Three Pillars

Zentara delivers this as one engagement combining an offensive testing program across the web and mobile estate with a structured remediation and retest cycle. Each finding is supported by evidence and a validated fix, so every issue raised gets a concrete answer.

Pillar

Focus

1 · Web Application Penetration Testing

Grey-box testing of the orado.co.id platform aligned with the OWASP Top 10 (2025), ASVS, and WSTG — covering authentication, authorization, session management, injection, and business-logic testing, plus API-layer endpoints (REST, GraphQL, SOAP) against the OWASP API Security Top 10 (2023).

2 · Mobile Application Penetration Testing

Grey-box testing of the Android application aligned with the OWASP Mobile Top 10 (2024) — static (SAST) and dynamic (DAST) analysis, reverse engineering, and code-tampering testing.

3 · Remediation, Retest & Knowledge Transfer

Prioritized technical remediation guidance, a knowledge-transfer session with the ORADO IT team, and a retest that validates the effectiveness of every fix.

Measurable remediation, not just a list. Every finding closes the loop — reproduce, rate, remediate, retest. Zentara re-tests each fixed issue and records the outcome in a retest report before the engagement ends.

05 Testing Methodology — WAPT (Grey-Box)

The engagement follows Zentara’s VAPT methodology: a hybrid of automated tooling for coverage and manual exploitation for depth, executed by senior operators and governed by rules of engagement and an NDA. Reporting is dual-layer — an executive summary and a detailed technical report.

Phase

Focus

Key Output

1 Scoping & RoE

Confirm scope, off-peak windows, escalation, and legal authorization; sign the NDA

Signed RoE & NDA

2 Reconnaissance

Surface mapping, endpoint and API enumeration across web and mobile

Attack-surface map

3 Web & API Testing

Grey-box exploitation — access control, auth, session, injection, business logic, API tier

Proven web / API findings

4 Mobile Testing

Android SAST + DAST, reverse engineering, and code-tampering testing

Proven mobile findings

5 Reporting

Executive summary plus technical report with severity matrix, CVSS v3.1, and PoC

WAPT report (dual-layer)

6 Remediation & Retest

Knowledge-transfer session, retest of each fix, and a consolidated final report

Closure validation

STANDARDS: OWASP Top 10 (2025) · OWASP Mobile Top 10 (2024) · OWASP API Security Top 10 (2023) · OWASP ASVS · OWASP WSTG · NIST SP 800-115 · CVSS v3.1

Hybrid, by senior operators. Automated tooling gives coverage; senior pentesters (OSCP, eWPT, eWPTX, CEH) give depth — both the web and the mobile assessment are run by senior operators. Every reported finding is manually validated.

06 OWASP Coverage — Web (2025) & Mobile (2024)

6.1 OWASP Top 10 (2025) — Web Platform (orado.co.id)

ID

Risk

What Zentara Tests

A01:2025

Broken Access Control

IDOR and privilege escalation on member, athlete, and tournament records; forced browsing

A02:2025

Security Misconfiguration

Headers, TLS, CORS, verbose errors, default configs, and exposed admin panels

A03:2025

Software Supply Chain Failures

Vulnerable / outdated components and third-party script integrity

A04:2025

Cryptographic Failures

TLS strength, sensitive data in transit and at rest, token and password storage

A05:2025

Injection

SQL / NoSQL, command, and XSS across registration and tournament inputs

A06:2025

Insecure Design

Business-logic abuse — registration and tournament workflow bypass

A07:2025

Authentication Failures

Credential stuffing, weak session management, MFA gaps, account takeover

A08:2025

Software or Data Integrity Failures

Unverified updates, deserialization, and integrity of critical data flows

A09:2025

Security Logging & Alerting Failures

Detection gaps for authentication abuse and high-risk actions

A10:2025

Mishandling of Exceptional Conditions

Error and edge-case handling, fail-open logic, and information leakage

6.2 OWASP Mobile Top 10 (2024) — Android Application

ID

Risk

What Zentara Tests

M1

Improper Credential Usage

Hardcoded or insecurely stored credentials and tokens in the app

M2

Inadequate Supply Chain Security

Vulnerable third-party SDKs and libraries

M3

Insecure Authentication / Authorization

Session and authorization handling between the app and backend

M4

Insufficient Input / Output Validation

Injection and data manipulation via app inputs and API calls

M5

Insecure Communication

TLS validation, certificate pinning, and data in transit

M6

Inadequate Privacy Controls

Excessive data collection and handling of personal data

M7

Insufficient Binary Protections

Reverse-engineering and code-tampering resistance

M8

Security Misconfiguration

Debuggable builds, excessive permissions, and exported components

M9

Insecure Data Storage

Sensitive data stored unencrypted on the device

M10

Insufficient Cryptography

Weak algorithms and key management

Access control and authentication lead. Broken access control (A01) and authentication failures (A07) top the web risks, and improper credentials (M1) top the mobile list. The grey-box design puts the heaviest manual effort exactly there.

07 Scope of Work

7.1 Assessment Types

☑ Web Application Security Assessment

☑ Mobile Application Security Assessment (Android)

☐ API & Web Services Security Assessment (covered within the web engagement)

☐ ISO 27001:2022 ISMS Assessment

☐ External / Internal Network Infrastructure Assessment

7.2 Approach

☐ Black-Box — no prior information provided

☑ Grey-Box — the testing team is given limited knowledge or user-level credentials

☐ White-Box — full system detail, including source code and administrative access

7.3 Assets In-Scope

Testing is authorized only for the assets agreed and listed below.

Asset (Type / Application)

Service

Environment

ORADO Web Platform (orado.co.id)

WAPT — Web

Production

ORADO Mobile Application (Android)

WAPT — Mobile

Production

7.4 Assets Out-of-Scope & Limitations

Any asset not explicitly listed as in-scope is out-of-scope. The following are strictly prohibited:

— Denial of Service (DoS / DDoS), automated brute-force without rate limits, and destructive exploitation affecting live database integrity.

— Social engineering of any form — phishing, smishing, or vishing against employees.

— Testing against any system, application, network, or infrastructure not on the approved target list.

— High-risk scenarios outside agreed off-peak hours.

Authorization boundary. Zentara will not test any asset outside the in-scope list without written approval. All activity follows OWASP best practice and is conducted with care for the stability of production services.

08 Compliance & Regulatory Alignment

The engagement produces evidence of independent security testing — supporting ORADO’s obligations under Indonesian law and its accountability to members, partners, and regulators.

Regulation / Standard

Relevance to This Engagement

UU No. 27/2022 — Personal Data Protection (PDP)

Independent testing supports accountability for protecting member and athlete data. Administrative fines reach 2% of annual revenue; criminal fines of Rp4–6 billion and 4–6 years apply to unlawful data handling.

PP No. 71/2019 — Electronic Systems & Transactions (PSTE)

Electronic system operators must guarantee the security and reliability of their systems and protect personal data. A WAPT evidences that duty of care.

OWASP & NIST SP 800-115

Industry-standard testing coverage — OWASP Top 10, Mobile Top 10, ASVS, and WSTG under the NIST SP 800-115 methodology — demonstrating due diligence.

Testing as evidence. A validated WAPT report — with a retest confirming closure — is objective proof to members, regulators, and leadership that ORADO’s public applications were independently assessed against recognized standards.

09 Deliverables

ORADO receives a complete, actionable package — built for both leadership and engineering.

— Executive Summary Report — risk posture and business impact for leadership.

— Detailed Technical Report — a Vulnerability Severity Matrix, proof-of-concept evidence, and remediation recommendations, each finding CVSS v3.1 rated.

— Retest Report — validating remediation of each finding.

— Final Report — consolidating the assessment and post-remediation status.

— Knowledge-transfer session — with the ORADO IT team.

4 Reports

Exec · Technical · Retest · Final

CVSS v3.1

Severity matrix

PoC

Evidence per finding

Retest

Closure validated

10 Delivery Timeline & Team

The engagement is scheduled across a July 2026 window. Web and mobile testing are both delivered by senior pentesters; detailed scheduling is confirmed at kick-off.

Stage

Window (July 2026)

Focus

Kick-off & Scoping

Week 1

RoE, NDA, off-peak windows, and target confirmation

Web + Mobile Testing

Early July

Grey-box web, Android, and API-layer testing

Reporting

Week 2

Executive + technical report, CVSS v3.1, severity matrix

Remediation (ORADO)

Mid-July

ORADO applies fixes with Zentara advisory

Retest & Final Report

End July

Per-finding closure validation and consolidated final report

Role

Responsibility

Certifications

Project Manager

Single point of contact; planning, scheduling, scope and quality control; NDA and Rules of Engagement; reporting and acceptance

PM · GRC

Senior Pentester — Web

Grey-box web and API-layer testing; manual exploitation; PoC evidence; retest

OSCP, eWPT, eWPTX, CEH

Senior Pentester — Mobile

Android SAST / DAST, reverse engineering, and code-tampering; PoC evidence; retest

OSCP, eWPT, CEH

Senior operators, production-safe. Both the web and mobile assessments are executed by senior pentesters under a defined methodology and quality-review process — with a proven track record of assessing live production environments without service disruption.

Outcome & next steps

Outcome & next steps

Delivered in July 2026: grey-box testing of the web platform, Android app and API layer against the OWASP Top 10 (2025), Mobile Top 10 (2024) and API Security Top 10 (2023); executive, technical, retest and final reports, with every finding reproduced, CVSS v3.1 rated and paired with remediation guidance; a knowledge-transfer session with ORADO's IT team; and a retest validating each remediated finding.

Related capabilities