3 ms·
> This is where my analysis and research ended, I did not attempt to enumerate any IAM permissions [...] I'm simply curious, is this standard (or a popular) et
by vemv 5y ago
> This is where my analysis and research ended, I did not attempt to enumerate any IAM permissions [...]
I'm simply curious, is this standard (or a popular) etiquette among security researchers?
- noasaservice 5y agoPretty much, yep. Once you get creds, you stop and report. You don't use, you don't enumerate, you dont do shit with them. Getting and reporting is good faith. Getting and using is likely starting a felony case.