A penetration tester discovers passwords in a publicly available data breach during the reconnaissance phase of the penetration test. Which of the following is the best action for the tester to take?
Upon discovering passwords in a publicly available data breach during the reconnaissance phase, the most ethical and constructive action for the penetration tester is to contact the client and inform them of the breach. This approach allows the client to take necessary actions to mitigate any potential risks, such as forcing password resets or enhancing their security measures. Adding the passwords to a report appendix (option A) without context or action could be seen as irresponsible, while doing nothing (option B) neglects the tester's duty to inform the client of potential threats. Using the passwords in a credential stuffing attack (option D) without explicit permission as part of an agreed testing scope would be unethical and potentially illegal.
Moon
11 months agoBrock
11 months agoStephen
11 months agoFrancoise
11 months agoVenita
11 months agoSheridan
11 months agoLajuana
12 months agoProvidencia
12 months agoDomingo
1 years agoAbel
1 years agoBambi
12 months agoShizue
12 months agoLajuana
1 years agoMarjory
1 years agoNan
11 months agoJohnna
11 months agoMurray
11 months agoRoyal
11 months ago