20
Reading a pentest report from 2014 taught me more than 3 courses
Went digging through old client files for a compliance question and found a report from a pentest done on infrastructure that's still in use, just updated. The tester nailed the same misconfig we fought with last month, and the cited CVE from 2014 got patched in 2016, but nobody checked the note about the follow-on issue. That one paragraph saved us a day of troubleshooting. Made me wonder how many current Ops teams actually read the notes sections of old reports vs just the executive summary. Has anyone else found a useful nugget buried in a legacy document like that?
1 comments
Log in to join the discussion
Log In1 Comment
stella_lee3d ago
That note about follow-on issues is like the fine print nobody reads until it bites them later lol.
0