 |
| |
| |
|
Who's Online |
|
We have 32 guests and 1 member online |
|
| |
|
|
 |
|
EH-Net
|
|
May 24, 2013, 01:37:52 PM
|
Show Posts
|
|
Pages: [1]
|
|
3
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Post Pen Test Hack Question
|
on: June 21, 2012, 09:56:36 AM
|
|
"On the flip side of this, the reality is, if someone compromised a glaring vulnerability, chances are the tester sucked (for lack of better words). Sorry I call it how I see it. In an instance where this occurs (you do a test and leave gaping holes) kiss any future business goodbye as well as introducing a huge black eye on your company."
you never worked where aj and I have... LOL Had black eyes and missing teeth but still got a lot of business.
|
|
|
|
|
5
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: reliable remote code execution for IIS on Server 2008?
|
on: June 20, 2012, 09:53:54 AM
|
|
It had to do it by sending syn packets with scapy and backing off TTL until the firewall responded with an error packet containing its IP, finding out that the firewall was misconfigured and had its config interface in front of me, guessing the correct password, dumping its config, ssh tunneling through the firewall and proxy scanning the server, enumerating some users, discovering a user with pass as user, looking in the sysvol, finding a bat script with domain admin permissions and rdp. So still not just IIS or web app but just pure luck. I think that is vague enough to not give up any confidential data but informative enough to "share". :-)
|
|
|
|
|
Loading...
|
|
 |
|