The $0 Checkout
Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.
Picture this: A software company on the brink of launching their flagship SaaS application. Marketing was counting down to go-live and the engineers were confident their CI/CD pipeline had caught every bug, but, before flipping the switch, they brought in Raxis to put the product through its paces as the final gate in their DevSecOps process.
Our web application pentester zeroed in on the checkout flow and noticed something familiar: the pricing logic was being calculated client-side, with no validation happening on the server. Using Burp Suite to intercept the request, our tester rewrote the total from full retail down to $0.00 and let the transaction fly. The server happily accepted it. The order processed, the payment confirmed at zero dollars, and had this been production, the product would have shipped, free of charge, to anyone clever enough to open a proxy.
While the web app pentester digested that finding, our external network tester was already at work. The server hosting the application was running a version of SSH with a high-risk, publicly exploitable CVE, a quiet welcome mat for any attacker with a working proof of concept.
Raxis reported on both issues in detail and with remediation recommendations, and the client got moving. Developers rebuilt the pricing logic to enforce server-side validation, the server team patched SSH, and, when Raxis returned for the complimentary retest, every finding came back remediated. The application launched on time, on budget, and most importantly, secure. That is the power of testing before production: catching the critical issues while they are still cheap to fix and turning a potential disaster into a clean, confident launch.