Edit: I missed that part,sorry.
Edit: I missed that part,sorry.
>In this case, on the other hand, it was the same Windows domain passwords that were used to authenticate against the VPN, so I could get a good user password, including that of the domain admin. Now I had full access to his network
That's scary. Maybe I'll need to badger my boss about a serious pentest of everything.
Fired them, and good riddance. But... STUPID SIMPLE things can get overlooked for years until you have someone else come in and test.
+1 for pentests.
That is no longer the case. To answer your question though, you know how hard it is to fire a CFO? Let me know if you have any tips.
GP wrote that he replaced the previous CTO.
Before firing the vendor, the responsible party on their side had already left the role.
https://mobile.twitter.com/DDoSecrets/status/119621668503812...