- Objective
- Break into the CRM vendor's internal infrastructure starting from open sources alone
- Path
- We started with OSINT: a breach dump contained working employee credentials for the internal portal. An IDOR flaw let us enumerate users — and surfaced a manager account with a default password. Through the portal's settings we uploaded a web shell and entrenched ourselves on the server. There we found an ansible.key — a key granting root access to 22 company servers at once. One leaked low-privileged account meant total control over the vendor's entire infrastructure.
- Detected
- The user enumeration blended into normal activity, the default-password login raised no alerts, and the web shell landed through a legitimate portal setting
After: The client received not a report but a map of a real attack — from first touch to full takeover. We eliminated the IDOR, disabled default passwords, isolated the Ansible keys and closed the internal portal to external access.