Tip No. 8 – Search for the forgotten
Look for applications, directories, and anything in pre-production; it is common for developers to use things in pre-production and over time forget about them. We can find users and passwords from a login or simply find a misconfiguration or something done or tested, leaving it vulnerable. This can certainly be an entry point to build a penetration or a more sophisticated attack.
I will share with you a personal experience. I once found a forgotten website in which I analyzed the source code, and to my surprise, I found in the source code a username and password, plus the URL to access and log in.