Sample report · External network penetration test

Network Penetration Test

An external network penetration test that started cold on the internet — and finished inside private cloud infrastructure with administrative and IAM credentials in hand.

What happened

OSec breached the external perimeter, reached internal systems and private AWS infrastructure, and pulled administrative and IAM credentials from an uninitialised InfluxDB instance — a single critical chain, plus twelve more findings.

Scope. The external network perimeter, including internet-facing web applications and cloud infrastructure.

What’s inside

The report, section by section

  1. Executive summary
  2. Scope
  3. Rules of engagement
  4. Findings summary
  5. Walkthrough (step-by-step)
  6. Conclusion

The findings

  • Uninitialised InfluxDB instance leading to account takeover
  • GitLab username disclosure
  • Source code disclosure
  • Path traversal in file create
  • Unauthenticated API access
  • Unauthenticated GraphQL introspection enabled
  • Username enumeration
  • Insecure XML-RPC functions enabled
  • API keys disclosed in source code
  • CORS arbitrary origin sharing
  • Host running an unmaintained operating system
  • Vulnerable and outdated components
  • Information disclosure via response headers

Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.

The document

Preview the report. Unlock the whole thing.

Unlock the full report ↓

The opening pages are free to read. Unlock the full 44-page report →

Unlock it

The full report here, plus all three as PDFs.

Drop your work email: the preview above unlocks to the full document, and we’ll send this report plus the other two as downloadable PDFs.

We’ll email the download links to that address.