Hacker News new | ask | show | jobs
by ratg13 626 days ago
At a previous job I worked with a really good contract pen-tester.

He would literally just walk into facilities and ask people to give them their passwords and they would give them.

The people working would also help him open wiring cabinets so he could do whatever he wanted.

2 comments

You aren’t wrong.

I called a vendor once, wanting a server setting tweaked. I asked for the present state and when it came back completely different to what I was expecting I backtracked.

I’d queued changed on a competitors live environment. I don’t think you need an elaborate charade, just blaze in with confidence.

Or walk past the boss's PA's desk, note if s/he has a photo of a cat/dog/boyfriend/girlfriend, ask someone the name of that companion and boom, there's your password.