Cyrex partnered with Soleil Ltd to conduct grey box penetration testing for RockShot, securing backend APIs, authentication flows, in-game transactions, and multiplayer systems across PvP and PvE modes.
RockShot is a free-to-play dynamic shooter featuring PvP and PvE modes, weapon customization, and competitive multiplayer systems. While core gameplay mechanics are central to the experience, non-gameplay services underpin player progression, monetization, and social systems.
Soleil Ltd required structured security validation across backend and service-layer components, including:
In free-to-play titles with in-game economies and competitive environments, vulnerabilities in backend services can impact progression, monetization integrity, and player trust.
Cyrex conducted comprehensive grey box penetration testing, combining architectural awareness with real-world attack simulation.
The engagement focused specifically on non-gameplay functionalities to ensure secure validation of core service components.
We evaluated:
The objective was to ensure that backend services properly validated user actions and restricted unauthorized access.
Cyrex also assessed:
We tested whether economic and social systems could be manipulated through parameter tampering, logic flaws, or improper authorization.
Through structured testing, Cyrex identified multiple vulnerabilities, many deemed high priority by the development team.
We delivered:
This enabled Soleil Ltd to address issues efficiently and reinforce backend security controls.
Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.
Response time: <24 hours • NDA included • No commitment required