CaptiveCrunch: When the Network Is the Phish
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →Perimeter exposure, internal lateral movement, identity boundaries, and the cloud misconfigurations that turn one foothold into a full compromise.
27 posts
CaptiveCrunch turns the captive portal itself into the phish, and MFA does not answer it. How the chain works, and what your simulations never covered.
Read the post →Public WiFi is safer than it used to be, and the network is no longer the main risk when you travel. What to set up before you go, and what to avoid.
Read the post →DNSDumpster shows you the same public DNS picture an attacker starts from. How to use it to map your own external attack surface, for free, this afternoon.
Read the post →Dashboards enumerate assets. None of that is defence. Why discovery does not equal security, and where identity multiplies an exposure into a breach.
Read the post →The findings we reported most often on external network engagements in 2025, ranked, with what each one usually means about the environment behind it.
Read the post →External assets stay the most attacked entry point into any organization. What external testing looks like in 2026, and how we approach the engagement.
Read the post →What a network penetration test involves, stage by stage: scoping, enumeration, exploitation, privilege escalation, and the lateral movement that follows.
Read the post →Cloud, mobile, remote work, and third parties expand what you expose without anyone deciding to. What attack surface management covers, and why it never stops.
Read the post →Default credentials are the shortest path from the outside to full control, and they are still everywhere. Where we find them, and how to hunt yours down.
Read the post →Staging and QA environments hold production data and get a fraction of the hardening. Why they keep appearing in findings, and how to get them off the internet.
Read the post →MAC address whitelisting is treated as a control. On a recent wireless engagement we were past it in minutes, and here is exactly how that went.
Read the post →Secrets committed to Bitbucket stay in the history long after the file is deleted. Why repositories leak credentials, and how to scan for them properly.
Read the post →SharePoint is a credential goldmine on internal engagements, because somebody always uploaded the spreadsheet. How we find them, and how to clear them out.
Read the post →Moving a service off port 443 hides it from nobody. Why non-standard web ports are indexed anyway, and what to do about the ones you did not know were open.
Read the post →Password complexity rules help, right up to the point they push people into predictable patterns. What actually resists cracking, and how to prove it.
Read the post →Port 3389 exposed to the internet is remote desktop left unlocked. What Shodan shows an attacker about your network before a single packet is sent to it.
Read the post →Credential stuffing is unsophisticated and works anyway, because people reuse passwords. How the attack runs, and which controls actually blunt it.
Read the post →An internal penetration test answers the question an external one cannot: what happens once somebody is already inside. The process, and the usual findings.
Read the post →An external penetration test covers everything an attacker can reach from the internet without credentials. What is in scope, and what the results tell you.
Read the post →Shared local administrator passwords are how a single workstation becomes the whole domain. Why the accounts are risky, and what to do instead of removing them.
Read the post →TLS 1.0 through 1.3, what changed at each step, and why a scanner still complains about the old ones. A short guide to which versions to turn off, and when.
Read the post →A flat network means one compromised host reaches everything. What belongs in a DMZ, what controls it needs, and how segmentation limits a breach.
Read the post →External attack surface management means finding what you expose to the internet before somebody else does. Why the inventory is always bigger than expected.
Read the post →Your scanner flagged an SSL certificate signed with a weak hashing algorithm. What that actually means, why SHA-1 fails, and how to replace the certificate.
Read the post →Zero trust is not a product you buy. It is the assumption that nobody inside or outside your network is trusted until they prove who they are, every time.
Read the post →Default credentials turned up in five of our last five engagements, and several led straight to critical access. Why this keeps happening, and the fix.
Read the post →Passwords on a notepad, in a spreadsheet, or the same one everywhere. Here is why a password manager fixes the single habit attackers rely on most.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.