PT0-002 · Question #363
During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to…
The correct answer is D. Report the findings to the customer's technical contact immediately. When a penetration tester discovers a critical vulnerability, such as hard-coded credentials leading to PII exposure, they must immediately report it to the customer's technical contact. This urgent notification is crucial to prevent further data compromise and allow the…
Question
During an engagement with a financial institution, a penetration tester found hard-coded credentials in a publicly accessible code repository. Those credentials allowed the penetration tester to access PII from many of the institution's customers and services that are hosted by a cloud provider. Which of the following actions should the penetration tester do next?
Options
- AProceed with the engagement and add the evidence in the final report
- BKeep the found credentials and use them during the engagement
- CDisclose the findings through a bug bounty platform
- DReport the findings to the customer's technical contact immediately
How the community answered
(46 responses)- A2% (1)
- B4% (2)
- C13% (6)
- D80% (37)
Why each option
When a penetration tester discovers a critical vulnerability, such as hard-coded credentials leading to PII exposure, they must immediately report it to the customer's technical contact. This urgent notification is crucial to prevent further data compromise and allow the organization to mitigate the risk promptly.
Proceeding with the engagement without immediate notification of a critical finding like PII exposure is irresponsible and unethical, as it delays mitigation of an active threat.
Keeping and using credentials that expose PII without immediate disclosure is unethical and could lead to further compromise or liability for the tester.
Disclosing findings through a public bug bounty platform before reporting to the customer is inappropriate and could expose sensitive information to a wider audience, violating client trust and data privacy.
Best practice and ethical guidelines for penetration testing require immediate reporting of critical findings, especially those involving PII exposure, to the designated customer contact. This allows the client to take rapid action to mitigate the severe risk and prevent further compromise.
Concept tested: Penetration testing ethics and critical vulnerability reporting
Topics
Community Discussion
No community discussion yet for this question.