CYREX
Back to Portfolio
Security Testing

MovieStar Planet 2

Client:MovieStarPlanet

Cyrex partnered with MovieStarPlanet to conduct grey box penetration testing for MovieStarPlanet 2, securing its mobile and browser platforms against business logic flaws, access control weaknesses, and session vulnerabilities.

The Challenge

Securing a Cross-Platform Social Game for Younger Audiences

MovieStarPlanet 2 is a social fashion game available on mobile (iOS and Android) and browser platforms. Designed for younger audiences, the platform enables users to chat, share content, customize avatars, and decorate virtual homes.

With social features and cross-platform access, the attack surface included:

  • Account and session management
  • Business logic handling
  • Access control enforcement
  • Client-side and browser-based vulnerabilities
  • Availability risks (DoS threats)

Given its audience and social nature, security vulnerabilities could impact user safety, platform integrity, and brand reputation.

The development team required structured penetration testing to identify weaknesses before malicious actors could exploit them.

The Cyrex Solution

Two-Week Grey Box Penetration Testing Engagement

Cyrex conducted comprehensive grey box penetration testing over a two-week period, covering both mobile and browser environments.

The engagement evaluated application logic and exposed endpoints across:

  • iOS and Android applications
  • Modern browser-based platform

Core Security Assessment Areas

Our testing included detection of:

  • Business logic flaws
  • Access control vulnerabilities
  • Session management weaknesses
  • HTML injection issues
  • Denial of service threats
  • Open redirection vulnerabilities
  • Frame injection points

We assessed whether server-side validation and session controls properly enforced user permissions and prevented manipulation.

Vulnerability Identification & Remediation

During the engagement, Cyrex identified nearly forty security flaws, with sixteen deemed critical by the development team.

We delivered:

  • A comprehensive security report
  • Clear descriptions of exploit scenarios
  • Practical remediation guidance aligned with best practices

The development team secured the vulnerabilities within weeks following our recommendations.

The Outcome

Reduced Exploit Risk & Strengthened Platform Integrity

  • Identification and remediation of critical business logic and access control vulnerabilities
  • Improved session management enforcement
  • Reduced risk of exploitation affecting user data and gameplay
  • Increased confidence in cross-platform security

Client Feedback

Discovering these issues early has probably saved us a ton of dollars and headaches fighting hackers and corrupted data. We were really impressed by the skills Cyrex proved to hold. We hire people to create stuff and creators don’t necessarily have that ‘criminal mind-set’ that Cyrex clearly do. We will continue to work with Cyrex in the future, simply because it’s a good business case with a great ROI.
Caspar Strandbygaard
CTO, MovieStarPlanet
CYREX VERIFIED

Don't Let Players Find the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required