A tale of enumeration, and why pen testing can’t be automated
ID: d7499005-5f17-548d-8cda-65bd20b50367
STIX ID: report--d7499005-5f17-548d-8cda-65bd20b50367
Feed Name: Pen Test Partners Blog
Threat Score
During an external penetration test an open public directory exposed a zipped ArcGIS proxy.config containing plaintext credentials that allowed access to the client's ArcGIS instance and enumeration of Active Directory and Office 365 user information; the client removed the directory and rotated credentials, and the report recommends regular audits, stronger environment segregation, MFA, and use of secret managers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
