24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//E-Commerce · 2025
E-Commerce · Case 2025

OWASP ASVS L2 pentest on a PCI-DSS scope e-commerce platform · 3M customers · 14 business days

A full-scope Red Team over 14 business days before Black Friday for one of Turkey's top 5 e-commerce platforms. 12 services · web + mobile + API · payment + coupon + cart + admin. PCI-DSS scope · 3M MAU · 8M card records. 3 Critical + 7 High + 12 Medium · all closed before Black Friday.

Duration
14 business days + 4 days of retest
Scope
3M MAU · 8M cards · 12 services · PCI-DSS scope
Customer Satisfaction
★★★★★

01 The Challenge

With 18 days to Black Friday the CTO requested an urgent pentest · the previous year a rival platform had suffered a card data leak. 3M active customers · 8M registered cards · a PCI-DSS scope annual audit in 6 weeks. 12 services (auth · payment · card · cart · coupon · vendor · return · search · review · stock · CMS · CRM). OWASP ASVS Level 2 mandatory · a certified QSA audit also approaching. DSET would perform a full-scope test with a hybrid methodology (automated + manual business logic).

02 DSET's Approach

01

Week 1 · Scope + recon

260 API endpoints · 23 subdomains (4 staging exposed) · 187 cookies · CSP/HSTS audit. Repo access for SAST + a staging environment for DAST. A threat model + attack scenarios were produced.

02

Week 2 · Business logic tests

Critical finding #1: staging.api.* auth bypass → production user enumeration. Critical #2: a coupon stack attack 18 coupons · -97% discount. Critical #3: viewing another user's order detail via IDOR.

03

Week 2 · Race condition + payment

A 200ms race condition between stock check and reserve · an arbitrage attack was proven. A currency manipulation test on the payment gateway · 1 high finding.

04

Week 2 · Instant critical alert

3 Critical findings were communicated to the customer before the pentest was completed. Patching began in parallel in Weeks 2-3. It was done in time for Black Friday.

05

Week 3 · Authorization + file

Authorization bypass attempts for the admin panel · vendor portal SSRF + file upload (a web shell attempted and the patch verified). A sub-domain takeover scan · 1 medium.

06

Week 3 · Mobile + API contract

iOS + Android app reverse engineering · API contract testing · jailbreak/root detection bypass. Mobile 4 medium · 2 low findings.

07

Re-test + report

All 30 findings · 28 closed (2 low to Q1). A 3-layer report: executive summary (2pg) + manager (12pg) + technical (226pg). To be submitted to the PCI-DSS QSA audit.

03 Results in Numbers

30 (3C + 7H + 12M + 8L)
Total Findings
T+12 (6 days before BF)
Critical Closure Time
28/30 (93%)
Re-test Closure
0 breaches
Black Friday Incidents
11 (all blocked)
Attack Attempts (BF)
Full compliance · no observations
PCI-DSS QSA Result

04 Customer Testimonial

"

They reported 3 Critical findings to us in Week 2 and started patching · with 6 days to Black Friday they were all closed. The PCI-DSS QSA audit passed with no findings. DSET monitoring blocked 11 attack attempts on Black Friday night.

CISO
E-Commerce Platform · Top 5 in Turkey
★★★★★

05 Key Takeaways

For OWASP ASVS L2 a hybrid methodology (automated + manual business logic) is essential · DAST alone is not enough
Critical findings with instant alerting + parallel patching · waiting for the end of the pentest is a luxury
A 3-layer report (executive + manager + technical) supports correct decisions for the board
The pair of pentest + live monitoring · catches a trigger one by one on a peak event night

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms