3 ms·
Sometimes it's accidental (but probably not in this case). One time a customer came to us and asked us to PenTest their server, checking it stands up to a DDoS
by bArray 6y ago
Sometimes it's accidental (but probably not in this case).
One time a customer came to us and asked us to PenTest their server, checking it stands up to a DDoS. They said they owned the server and it was their network, so we said "we can run a small one for you which should give us an idea of some pain points".
We run the "mini" DDoS against the server, it takes a little more to sink the server than expected, but we just ramp up a few more connections and it is fine. We lift off on the test attack, but customer site doesn't come back up. We contact them and they say they will contact the VPS host. * Heart sinking moment *
We test other websites running on their cloud from a different connection - we had taken out their entire cloud infrastructure (this was a small provider). After a short while they were back up, but not before another few conversations with the customer. I really don't even want to know how badly positioned we were legally that day.
Lesson learned: Always double check.
- celicaraptor 6y agoDid you try to contact the provider to provide(heh) an explanation?
- bArray 6y agoI believe they were contacted yeah, but at that point I washed my hands of the project.
- technion 6y agoI won't forget having a pentester nmap a local network - it hard locked every single phone handset corporation wide. People had to walk around pulling the power out and putting it back in every single desk in multiple buildings.
- bArray 6y agoWow haha, I wonder what caused them to fail so badly?
- technion 6y agoI don't know but desktops used passthrough networking, so there wasn't a PC with network connectivity left.
- Twirrim 6y agoAt one place I worked, we had a printer that would die whenever the PCI-DSS auditors would run a network scan. There was a Windows vulnerability that came out in 2010-2011ish, when I was working there, that I had to deal with. I ran an nmap scan of the entire network looking for the bug, and accidentally BSOD'd half the office...