• XSS.stack #1 – первый литературный журнал от юзеров форума

Selling corp access to cloud company that manages many clients' backups

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

ksiao23

HDD-drive
Пользователь
Регистрация
02.11.2022
Сообщения
27
Реакции
11
English-speaking, I apologise in advance but am happy to use a translation tool to converse :) My work focuses mainly on the phish. I have gained multiple entry points to admin + non-admin accounts for a Brazilian cloud company that manages all cloud services and backups for an array of multi-million pound clients. Cloud company alone has a revenue of 2.2M, with its clients worth various amounts.

My work has enabled me to grab the key for its KeePass (.kdb) account. The KeePass contains over 100 unique logins with AnyDesk access to clients' backups. I also have the admin account for the companies MSP360 account, where multiple terabytes are centrally managed. Admin access to Microsoft Enta can handle user permissions and the Sharepoint has a deluge of passwords and usernames, all clear-text, to supplement the KeePass account. There are keys, certificates to OVPN, VPNs, RDPs.

My work in the moment after access has been locating the master key for KeePass and conducting surface recon to check the validity of the logins, which I can provide. No alerts have been raised. The berry is ripe for mass data exfil but is not scalable or my area of work, hence the sale. Screenshots can be provided and access to all of the above. I am also happy to provide a summary of my week's worth of recon to show exactly how the system is structured.

Please send me an inbox message. I will only work through a guarantor and the scope for good work in the hands of experts is very high due to the nature of the company's business. All of the above is valid and am happy to meet all requirements to vet the info provided.
 
English-speaking, I apologise in advance but am happy to use a translation tool to converse :) My work focuses mainly on the phish. I have gained multiple entry points to admin + non-admin accounts for a Brazilian cloud company that manages all cloud services and backups for an array of multi-million pound clients. Cloud company alone has a revenue of 2.2M, with its clients worth various amounts.

My work has enabled me to grab the key for its KeePass (.kdb) account. The KeePass contains over 100 unique logins with AnyDesk access to clients' backups. I also have the admin account for the companies MSP360 account, where multiple terabytes are centrally managed. Admin access to Microsoft Enta can handle user permissions and the Sharepoint has a deluge of passwords and usernames, all clear-text, to supplement the KeePass account. There are keys, certificates to OVPN, VPNs, RDPs.

My work in the moment after access has been locating the master key for KeePass and conducting surface recon to check the validity of the logins, which I can provide. No alerts have been raised. The berry is ripe for mass data exfil but is not scalable or my area of work, hence the sale. Screenshots can be provided and access to all of the above. I am also happy to provide a summary of my week's worth of recon to show exactly how the system is structured.

Please send me an inbox message. I will only work through a guarantor and the scope for good work in the hands of experts is very high due to the nature of the company's business. All of the above is valid and am happy to meet all requirements to vet the info provided.
Which company? Any sample available?
 
Статус
Закрыто для дальнейших ответов.
Верх