recruitenepal.
com
Security Audit Report
Dec 24, 2025
Student Name | Khagendra Singh Saud
Table of Contents
Security Audit Report .................................................................................................... 1
1. Executive Summary................................................................................................ 1
2. Scope of Assessment ............................................................................................. 1
In-Scope ................................................................................................................... 1
Out of Scope ............................................................................................................. 1
3. Methodology.......................................................................................................... 2
Phases: ................................................................................................................. 2
4. Tools Used ............................................................................................................ 2
5. Information Gathering & Reconnaissance ................................................................ 2
5.1 Domain Information .......................................................................................... 2
5.2 DNS Enumeration ............................................................................................. 3
6. Subdomain Enumeration ........................................................................................ 4
7. Technology Fingerprinting ....................................................................................... 5
Detected Technologies ........................................................................................... 5
8. Port & Service Analysis ........................................................................................... 6
Open Ports ............................................................................................................ 6
9. SSL/TLS Configuration Review ................................................................................ 6
10. Security Headers Analysis .................................................................................... 7
Observed Headers ................................................................................................. 7
11. Cookie Security Analysis....................................................................................... 8
Security Flags ........................................................................................................ 8
12. Vulnerability Assessment Summary ...................................................................... 9
13. Risk Impact Analysis ............................................................................................ 9
14. Recommendations ............................................................................................. 10
15. Conclusion ........................................................................................................ 10
Security Audit Report
Target Website: [Link]
Assessment Type: Web Application Security Audit (Passive & Non-Intrusive)
Date: 23 December 2025
Auditor: Khagendra Singh Saud
Role: Cybersecurity Intern
1. Executive Summary
This security audit report presents the findings of a web application security assessment
conducted on [Link], a job recruitment platform. The objective of this audit
was to identify potential security weaknesses, misconfigurations, and exposure points that
could be exploited by attackers.
The assessment was limited to reconnaissance, enumeration, and passive analysis. No
exploitation or intrusive testing was performed.
Overall Risk Rating: Medium
Key strengths observed include HTTPS enforcement, Cloudflare protection, and secure
cookie attributes. However, improvements are recommended in areas such as security
headers, SSL hardening verification, and application-level security testing.
2. Scope of Assessment
In-Scope
• Primary domain: [Link]
• Public-facing web services
• DNS and HTTP(S) services
• Passive vulnerability assessment
Out of Scope
• Denial-of-Service (DoS) attacks
• Brute-force attacks
• Exploitation of vulnerabilities
• Internal network testing
1
3. Methodology
The audit followed standard cybersecurity assessment practices aligned with: - OWASP
Web Security Testing Guide - NIST SP 800-115 (Technical Guide to Information Security
Testing)
Phases:
1. Information Gathering & Reconnaissance
2. Technology Fingerprinting
3. Vulnerability Identification (Passive)
4. Risk Analysis
5. Recommendations
4. Tools Used
Tool Name Purpose
WHOIS Domain & registrar information
nslookup / dig DNS enumeration
WhatWeb Technology fingerprinting
Nmap Port and service discovery
Nikto Web server misconfiguration checks
Browser DevTools Cookie and header inspection
5. Information Gathering & Reconnaissance
5.1 Domain Information
• Domain Name: [Link]
• Protocol: HTTPS
• Registrar: Namecheap (example)
• Hosting/CDN: Cloudflare
• IP Address: [Link] (Cloudflare protected)
Screenshot:
[WHOIS lookup result for [Link]]
2
5.2 DNS Enumeration
DNS records identified include: - A Record - AAAA Record - MX Record - NS Record
No sensitive internal IP addresses were exposed.
Screenshot:
[DNS records enumeration output]
3
6. Subdomain Enumeration
Subdomain enumeration was performed using passive tools.
Subdomain Status
[Link] Active
[Link] Discovered
[Link] Discovered
4
No evidence of subdomain takeover vulnerability was observed.
Screenshot:
[ Subdomain enumeration using subfinder -d [Link]]
7. Technology Fingerprinting
Detected Technologies
Component Details
Web Server Cloudflare
Frontend Framework React / [Link]
SSL/TLS TLS 1.2 / TLS 1.3
Cookies HttpOnly, Secure enabled
Screenshot:
[WhatWeb scan results]
5
8. Port & Service Analysis
Open Ports
Port Service State
443 HTTPS Open
80 Http Open
8080 Http-proxy open
No unnecessary ports were found exposed to the public.
Screenshot:
[Nmap scan showing open ports]
9. SSL/TLS Configuration Review
• HTTPS is enforced
• Valid SSL certificate detected
• Certificate issued by trusted CA
Potential Risk: Cipher strength and HSTS configuration need further verification.
Screenshot:
[SSL/TLS certificate details from browser]
6
10. Security Headers Analysis
Observed Headers
Header Status
Content-Security-Policy Partially Implemented
X-Frame-Options DENY
X-Content-Type-Options nosniff
Referrer-Policy no-referrer
Screenshot:
[HTTP security headers from browser DevTools]
7
11. Cookie Security Analysis
Cookies observed: - __Host-[Link]-token - __Secure-[Link]-url
Security Flags
• Secure:
• HttpOnly:
• SameSite: Partial
This reduces risk of session hijacking and XSS-based cookie theft.
Screenshot:
[Cookie details from browser storage]
8
12. Vulnerability Assessment Summary
Area Risk Level Description
SSL/TLS Hardening Medium Cipher strength unverified
Security Headers Medium Missing important headers
Input Validation Medium Forms require deeper testing
API Security Medium API endpoints need auth & rate-limit review
Server Exposure Low Cloudflare hides origin
13. Risk Impact Analysis
If exploited, identified weaknesses could lead to: - Clickjacking attacks - Cross-site
scripting (XSS) - Session misuse - Information disclosure
9
14. Recommendations
1. Implement missing HTTP security headers (X-Frame-Options, X-Content-Type-
Options)
2. Enforce HSTS and review SSL cipher suites
3. Apply strict input validation on all forms
4. Secure API endpoints with authentication and rate limiting
5. Conduct periodic vulnerability scans
6. Maintain Cloudflare WAF rules
15. Conclusion
The security posture of [Link] is reasonable for a public-facing web
application. Cloudflare protection and HTTPS implementation provide a strong baseline.
However, addressing the identified medium-risk issues will significantly improve overall
security and resilience against common web attacks.
10