2 ms·
I would recommend simply having a very generalised discussion on your infra from a birds eye view and see if they can provide some inferences, add/ suggest any
by rishabhd 5y ago
I would recommend simply having a very generalised discussion on your infra from a birds eye view and see if they can provide some inferences, add/ suggest any customised test/ use cases, share previous experience in similar infrastructure/ industry. Intent is not to assess them technically, afterall their biggest strength is that they are jack of all traits and master of something that might not even exist in your infrastructure. Their shared experience can help identify issues that you may not even consider since it was out of your work domain.
For example, my infra+hardware guy reported mousejack vulnerability as an extra observation during 2.4 Ghz spectrum security assessment. The core scope was wifi spectrum, but since he had an understanding of devices operating in that spectrum, he was able to compromise vulnerable wireless mice (logitech ones) at a client which operated in the same spectrum. Most OSWP guys don’t even know about it, you can have my word on it.