Oct 26, 2020 | Misconfiguration, Pentesting, Security, Vulnerabilities
While working with a client, VDA engineers encountered an interesting circumstance that allowed for the bypassing of Multi-factor Authentication for users that had already set this up on their accounts. This particular misconfiguration/vulnerability was possible due...
May 8, 2020 | AppSec, Pentesting, Security, Tool Development
Part of our internal mentoring and training culture at VDA includes Lunch and Learn events where engineers share helpful information about a relevant security topic. This past week, several of us discussed our favorite BurpSuite extensions, which are helpful additions...
Nov 7, 2019 | Auditing, Endpoint Security, Enterprise Security, OSINT, Pentesting, Training
Low-Hanging Fruit Series: Permissions At VDA Labs we work with a variety of companies both large and small. During our engagements, we see many of the same reoccurring issues that allow us access to systems. To help combat these threats VDA is starting a blog series...
Oct 31, 2019 | Enterprise Security, Pentesting, Phishing, Security, Social Engineering, Training
Low-Hanging Fruit Series: Multi-factor Authentication (MFA) At VDA Labs we work with a variety of companies both large and small. During our engagements, we see many of the same reoccurring issues that allow us access to systems. To help combat these threats VDA Labs...
Oct 1, 2019 | Pentesting, Phishing, Social Engineering, Training
Phishing Users using Evilginx and Bypassing 2FA Phishing is one of the largest ways that organizations are being compromised in 2019. The common recommendation is that all users should have two factor authentication (2FA) enabled on their accounts to help combat the...
Sep 25, 2019 | Enterprise Security, Exploit Development, Pentesting, Vulnerabilities
Objective In an effort to help make us all more secure, VDA decided to release a pentest technique, that we discovered a while ago. We notified Microsoft many months ago of this technique, and they have been a great partner as always, in quickly working to mitigate...