56

So...
I'm penetrationtesting a network and the servers on said network
The network administrator and IT security officer knows this, because they hired me..

TL;DR a scan caused the network to crash.

Today I received a very angry email going "Stop scanning NOW!" from one of the IT departments.

Apparently I crashed their login server and thus their entire network...
It happened d the first time I scanned the network from the outside and they had spend an entire day figuring out how and repairing the service they thought was the problem, but then it crashed again, when I scanned from within the network.

Now they want to send me a list of IP's that I'm not allowed to scan and want to know exactly what and when I'm scanning...

How crap can they be at their job, if they weren't able to spot a scan... The only reason they found out it was me was because the NA had whitelistet my IP, so that I could scan in peace...

Comments
  • 5
    Wtf, "IT security agent". They do understand that a hacker can do this also right?
  • 3
    @Jifuna Yeah, but it wasn't the officer that was the problem, it was the other department...
  • 1
    They don't already practice those? Pretty standard procedure where I am. Also, the fact a scan brought down services says a lot about the applications...and network design. Unless of course, it was a DoS vulnerability or brute force you were executing.
  • 5
    Good to see businesses are so open to listen to pros in order to upgrade their security...

    *plz i'm sarcastic*
  • 1
    @Wallpaper Nah, it was just a basic scan from Nessus
Add Comment