Reporting
We have successfully completed the penetration test and now must produce documentation. Your report should look professional, organized, and clearly explain the findings, and it should also set to non-technical language how these issues may have been overlooked. Focus on what allowed you to enter, but also make sure to point out when something worked such as the pam
restrictions encountered when attempting to add a password for the standard games account (which should technically not exist in an environment that claims to be secure).
Let's take a moment and break down the problems we encountered during this penetration test:
We were able to brute force a password that used upper case and lower case characters as well as numbers. The password was also over eight characters long which is fairly standard in a secured environment. At no time should a user ever use passwords that are based on a company name or other trivial fact. If someone has a page stating that they love football...