Identifier | Finding | Risk Rating |
---|---|---|
APP-01 | Stored Cross-site Scripting (XSS) |
High |
INT-01 | Kerberos Service Ticket Credential Theft |
High |
SOC-01 | Credentials Captured via Phishing |
High |
WIR-01 | Wireless Router Vulnerable to Pixie-Dust Attack |
High |
CSA-01 | Unquoted Service Path |
Moderate |
CSR-01 | Missing MFA on Root AWS Account |
Moderate |
EXT-01 | Email Spoofing - DMARC Policy Not Enabled |
Moderate |
MOB-01 | MFA Bypass |
Moderate |
This sample report showcases our services and highlights the depth of our testing, from reconnaissance to remediation. Included is one finding from each major service category we offer. Findings vary from Low to High risk, but always have a proven business impact. All of this to say: the sample report is a glimpse into the rigor, creativity and expertise we bring to every engagement, big and small.
Identifier | Finding | Risk Rating |
---|---|---|
APP-01 | Stored Cross-site Scripting (XSS) |
High |
INT-01 | Kerberos Service Ticket Credential Theft |
High |
SOC-01 | Credentials Captured via Phishing |
High |
WIR-01 | Wireless Router Vulnerable to Pixie-Dust Attack |
High |
CSA-01 | Unquoted Service Path |
Moderate |
CSR-01 | Missing MFA on Root AWS Account |
Moderate |
EXT-01 | Email Spoofing - DMARC Policy Not Enabled |
Moderate |
MOB-01 | MFA Bypass |
Moderate |
Last year alone, Schellman's pen test team had: