RiSec.n0tst3 22 February 2022
My team was recently engaged by a client (Hackme) to perform a black-box external penetration test. The objective was simple – see how susceptible the organization is from an external point of view and test the effectiveness of the security controls that are managed enterprise-wide. As such, asides, the company name, we were given “ZERO” information. The following details illustrate how we embarked upon this assessment which resulted in… OSINT 101 We kicked off with some Open Source Intelligence (OSINT) 101 :). There are quite a number of open...