Cyrex partnered with MovieStarPlanet to conduct grey box penetration testing for MovieStarPlanet 2, securing its mobile and browser platforms against business logic flaws, access control weaknesses, and session vulnerabilities.
MovieStarPlanet 2 is a social fashion game available on mobile (iOS and Android) and browser platforms. Designed for younger audiences, the platform enables users to chat, share content, customize avatars, and decorate virtual homes.
With social features and cross-platform access, the attack surface included:
Given its audience and social nature, security vulnerabilities could impact user safety, platform integrity, and brand reputation.
The development team required structured penetration testing to identify weaknesses before malicious actors could exploit them.
Cyrex conducted comprehensive grey box penetration testing over a two-week period, covering both mobile and browser environments.
The engagement evaluated application logic and exposed endpoints across:
Our testing included detection of:
We assessed whether server-side validation and session controls properly enforced user permissions and prevented manipulation.
During the engagement, Cyrex identified nearly forty security flaws, with sixteen deemed critical by the development team.
We delivered:
The development team secured the vulnerabilities within weeks following our recommendations.
“Discovering these issues early has probably saved us a ton of dollars and headaches fighting hackers and corrupted data. We were really impressed by the skills Cyrex proved to hold. We hire people to create stuff and creators don’t necessarily have that ‘criminal mind-set’ that Cyrex clearly do. We will continue to work with Cyrex in the future, simply because it’s a good business case with a great ROI.”
Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.
Response time: <24 hours • NDA included • No commitment required