Social Engineering Zoom Call

Challenge

Client engaged ivision for a red team assessment to gain visibility through real-world attack scenarios and simulation of how real attackers would exploit security gaps, providing a realistic assessment of an organization’s defenses.

Solution

Red team discovery uncovered several remote code execution (RCE) vulnerabilities in the target’s firewall product family. Posing as a prospective buyer, ivision obtained a live product demo and exploited one of the RCEs to rig the demo website with a credential collector; however, the credentials submitted contained a typo. A remaining RCE bug allowed the team to target individual firewalls using unique identifiers, granting them access to the target’s network and enabling the team to begin capturing flags.