(no title)
alaxapta7 | 2 years ago
The company made some basic port scan and established that we're running outdated and vulnerable version of Apache. I found the act of explaining the concept of backports to a "pentester" to be physically painful.
They didn't get paid and another company was entrusted with the audit.
pixl97|2 years ago
Hopefully you also have an internal control that looks at actual package versions installed on the server.
alaxapta7|2 years ago
dylan604|2 years ago