logoalt Hacker News

kevin_nisbettoday at 2:38 AM1 replyview on HN

>That’s assuming your vendor was pentesting AWS systems. If you meant you hired a vendor to pentest your own systems on AWS, that’s of course a totally different matter.

Sorry for being unclear, the vendor was attacking our organization only, and any other company was expressly forbidden in the contract. As I recall it was a fake SSO sign-in page to collect credentials that they would try and social engineer our employees with.


Replies

Shanktoday at 3:56 AM

At a minimum you should contact AWS before you launch a phishing page as a test that targets AWS customers.

show 1 reply