🕵️ Comprehensive Security Audit Report: CheckProof Ecosystem

Pentester: xzens

Target Domains: checkproof.com, admin.checkproof.com, api.checkproof.com, app.checkproof.com

Date: 25 February 2026 to 7 March 2026


1. Executive Summary

This report documents a series of security tests (Vulnerability Assessment) conducted on the digital infrastructure of CheckProof, an industrial asset management platform. The investigation included metadata analysis, server stability testing, and third-party library auditing.

Several critical vulnerabilities were identified which, when combined as chained vulnerabilities, could lead to sensitive data exposure and administrative account takeover (Account Takeover).


2. Phase 1: Passive Reconnaissance & Information Disclosure

The first phase involved passive reconnaissance techniques against the source code of the administrative application's front-end.

2.1. Ember.js Environment Leakage

The application uses the Ember.js framework, which by default stores configuration inside <meta> tags. It was found that the developers had included sensitive credentials in this public configuration.

Screenshot 2026-03-06 213302.png