Hackers can penetrate local networks in just 30 minutes hacker targeting a PC


New research from Positive Technologies has shed light on how easy it is for hackers to breach organizations’ local networks by exploiting known software vulnerabilities.
To compile its new Penetration Testing of Corporate Information Systems report, the firm’s experts performed external pentests on organizations in the finance, IT, fuel and energy, government, hospitality, entertainment and telecommunications industries.
In its tests, Positive Technologies was able to access the local network at 93 percent of tested organizations with the maximum number of penetration vectors detected at a single company being 13. Furthermore, in one out of every six tested companies, it found traces of previous attacks such as web shells on the network perimeter, malicious links on official sites or valid credentials in public data dumps, indicating that the infrastructure may have already been infiltrated by hackers.
The firm’s experts also found that penetration of a local network usually takes between 30 minutes and 10 days. However, in most cases, attack complexity was low which means that the attack was well within the capabilities of even a hacker with just basic skills.
Penetration testing
Positive Technologies’ research also found that brute force attacks were an effective way to crack credentials when launching attacks on web applications at 68 percent of the companies its team performed external pentests on.
If an attacker is able to successfully brute force the password for at least one domain account, they can discover identifiers for other users by downloading the offline address book which contains all of the email addresses for a company’s employees. In fact, at one of the tested organizations, the firm’s pentesters obtained over 9,000 email addresses using this method.
Head of research and analytics at Positive Technologies, Ekaterina Kilyusheva provided further insight on how organizations can perform their own penetration tests in a press release, saying:
“Web applications are the most vulnerable component on the network perimeter. In 77 percent of cases, penetration vectors involved insufficient protection of web applications. To ensure protection, businesses need to perform security assessments of web applications regularly. Penetration testing is performed as a “black box” analysis without access to source code, which means businesses can leave blind spots to some issues which might not be detected using this method. Therefore, companies should use a more thorough testing method as source code analysis (white box). For proactive security, we recommend using a web application firewall to prevent exploitation of vulnerabilities, even ones that have not been detected yet.”
New research from Positive Technologies has shed light on how easy it is for hackers to breach organizations’ local networks by exploiting known software vulnerabilities. To compile its new Penetration Testing of Corporate Information Systems report, the firm’s experts performed external pentests on organizations in the finance, IT, fuel and…
Recent Posts
- How Claude’s 3.7’s new ‘extended’ thinking compares to ChatGPT o1’s reasoning
- ‘We’re nowhere near done with Framework Laptop 16’ says Framework CEO
- Razer’s new Blade 18 offers Nvidia RTX 50-series GPUs and a dual mode display
- I tried adding audio to videos in Dream Machine, and Sora’s silence sounds deafening in comparison
- Sandisk quietly introduced an 8TB version of its popular portable SSD, and I just hope they solved its previous big data corruption issue
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010