A small number of ethical hackers are invited to find vulnerabilities & report them during joint bug bounty challenges between @Hacker0x01 & @DeptofDefense
I've won the challenges:
• Hack the Proxy
• Hack the Army 2.0
• Hack the Army 3.0
So,
12. I reported it & was awarded a bounty. One of many!
Want to hear more about securing US Defense assets?
On Jan 31st, I'll be chatting w/ @Hacker0x01's CTO @senorarroz
about securing US Defense assets!
The hacker social engineered an employee -> logged into the VPN and scanned their intranet. 👇
Apparently there was an internal network share that contained powershell scripts...
"One of the powershell scripts contained the username and password for a admin user in Thycotic (PAM) Using this i was able to extract secrets for all services, DA, DUO, Onelogin, AWS, GSuite"