SO talk about the time they were hacked. Matches what I say a lot. I'd never attack a prod website first, I'd attack the dev/test environments first. Big orgs act like only prod is worth of protection & or setup crazy policies that bring dev work to a halt
https://stackoverflow.blog/2021/01/25/a-deeper-dive-into-our-may-2019-security-incident/
Build servers are the keys to (some) kingdoms. If you can hack a build server, then who cares about active directory.
♡ 0 ↻ 0If you only get 1 thing out of this, the ability to make a build & deploy a build should be different servers, different people. If the deployer is a rubber stamp approval, tho, then no gain.
♡ 0 ↻ 0