3 ms·
Off-topic tale: This brings back the memory of my first serious security job, 14 years ago or so. I had to pen test a big corporate-like network from the inside
by ogig 10y ago
Off-topic tale: This brings back the memory of my first serious security job, 14 years ago or so. I had to pen test a big corporate-like network from the inside so I was left with my laptop in a cubicle and the mission to own something. I was young, inexperienced and a bit scared by the size of the network. After some minutes I had a general map of the network, there were some separated LANs and in the middle of them all it was this Avaya Cajun managed thing. I ran some google queries and the second or third result showed up a CVE, the Avaya firmware had a hidden admin account. Total time used, 10-15 mins.
I did not have to go any further, owning the Avaya was game over and got some pats on the back from my employer and the clients. I had prepared a quite extensive plan of action, been my first gig I had to show. The laptop was loaded of tools, even some "cool" exploits but at the end it all came down to a few nmap scans and a google query. I felt dissapointed. Also, after the pen test I spent some (very) boring weeks documenting, inventorying, and documenting again. It made me reconsider how deep I wanted to dive into security audits.