Case study · 03 · Security assessment
DataKing Penetration Test
A structured external penetration test conducted exactly the way an attacker would: from public information and breached credentials to a valid login, internal network access, and a full professional findings report with remediation.
What I did
Think like an attacker, write like an engineer.
The goal was to evaluate an organization's external security posture the way a real attacker would — no inside knowledge, no allowances, just the public attack surface. Every phase followed a defined methodology, and every result fed a report the client could act on.
- Planned the engagement around the NIST SP 800-115 Technical Guide to Information Security Testing, the OWASP Testing Guide (v4), and customized testing frameworks.
- Gathered open-source intelligence, including employee information and historical breached credentials, to use against external login services.
- Performed scanning and enumeration to identify vulnerabilities, then confirmed them through controlled exploitation.
- Executed credential stuffing and password spraying attacks against the Outlook Web App, eventually gaining valid credentials and access to the internal network through the VPN portal.
- Documented every finding with a CVSS-based severity rating, impact, affected system, and NIST control references.
- Delivered a full findings report with step-by-step remediation: MFA on external services, restricted logon attempts, and a stronger password policy.
How the test unfolded
Four steps from public data to full access.
No single exploit broke the network. Three ordinary policy gaps — reused credentials, unrestricted attempts, and a guessable password pattern — chained together into a critical path.
Open-source intelligence
Collected historical breached-credential dumps and employee information tied to the company — 868 account credentials in total — and flagged the risk of staff reusing work emails as logins on other services.
Credential stuffing & enumeration
Tried the breached credentials against the Outlook Web App login. The stuffing attack itself failed, but inconsistent error messages allowed username enumeration — a list of valid accounts to aim the next attack at.
Password spraying
Tested a predictable seasonal password pattern (season + year + special character) against every valid account. Because logon attempts were unrestricted, the pattern eventually matched — yielding a successful login to OWA.
Internal network access
Leveraged the valid credentials to log into the client VPN portal, reaching the internal network — and demonstrating how three small gaps combine into a critical, full-compromise path.
Findings & remediation
Every weakness came with a fix.
Findings were rated by CVSS severity, tied to NIST control references, and paired with specific, prioritized remediation steps the IT team could implement.
Missing multi-factor authentication
HighVPN and OWA logins accepted valid credentials with no second factor. Recommendation: implement and enforce MFA across all external-facing login services.
Weak password policy
HighA seasonal password pattern succeeded against valid accounts. Recommendation: 14+ character passwords, unique per account, no dictionary words or proper names — plus employee training and checks against known-breached passwords.
Unrestricted logon attempts
CriticalUnlimited attempts on external logins made brute force and password guessing practical. Recommendation: restrict logon attempts and automatically lock accounts, per NIST SP 800-53 AC-7(1).
Username enumeration
ModerateThe login page revealed which accounts existed. Recommendation: synchronize valid and invalid account messages so failures are indistinguishable.
What the client did right: SIEM monitoring
The internal security team detected the vulnerability scanning within minutes, identified the attacker's IP address, and blacklisted it from further scanning. Detection and response worked — the gaps were in authentication policy, not visibility.
Assessment
External penetration test · Simulated attacker with no inside knowledge
Frameworks
NIST SP 800-115 · OWASP Testing Guide v4 · CVSS severity ratings
Findings
1 critical · 1 high · 1 moderate · 1 low · Informational
Deliverable
Security Assessment Findings Report with remediation plan
Skills applied
Want the full picture?