Internal Infrastructure Penetration Testing

Case Study: Internal Infrastructure Penetration Testing

Internal networks are frequently treated as trusted once a device is connected. In practice, one unauthorised laptop, compromised endpoint or poorly controlled network port can expose name-resolution protocols, authentication relays, weak segmentation, unsupported systems and administrative services that were never intended to face an attacker.

This case study outlines a second-round ProCheckUp internal infrastructure penetration test for a multi-branch international bank. The engagement modelled an individual with physical access to the network and assessed whether that initial position could be extended towards identity services, business-critical 

Overview of an anonymised ProCheckUp internal infrastructure penetration test for an international bank showing approximately 550 internal addresses, three principal network zones, 22 findings, four Critical issues and the Discover, Validate, Chain and Prioritise methodology

Overview

An international bank commissioned ProCheckUp to repeat its onsite internal infrastructure penetration test and measure how much risk remained after an earlier remediation programme. The assessment covered a broad estate of endpoints, servers, network devices, printers, voice systems, security appliances and third-party-managed equipment.

The agreed threat model assumed that an attacker or unauthorised insider had obtained physical access to an internal network connection. ProCheckUp then tested whether that foothold could be used to enumerate services, bypass device-admission controls, intercept or relay authentication, cross network zones and reach systems important to banking operations.

The engagement identified 22 findings: four Critical, eleven High, six Medium and one Low. The most consequential evidence included a successful IPv6-based authentication relay to LDAP, extraction of Active Directory information, unauthenticated access to a business-critical application, a freely mountable NFS share, weak separation between application and core-banking zones, default device credentials and vulnerable legacy platforms.

Engagement at a glance

  • - Approximately 550 internal addresses assessed through targeted and representative sampling
  • - Application, core-banking and vendor-managed equipment zones included
  • - Multi-branch onsite insider-threat perspective
  • - Endpoints, servers, switches, security appliances, printers and voice devices reviewed
  • - Identity relay, segmentation, service exposure and device-admission controls manually validated
  • - Second-round comparison distinguished genuine improvement from residual systemic risk

Challenge

Internal infrastructure testing in a live banking environment required broad technical coverage without disrupting essential services. The assessment also had to distinguish a confirmed attack path from a potential consequence and a version-based vulnerability indication from exploitation that had actually been demonstrated.

A heterogeneous estate with different owners

Standard endpoints, directory services, core applications, embedded printers, voice devices, switches and vendor-managed equipment followed different patching, credential and lifecycle models. A control applied effectively to one device class could be absent from another.

Evidence without operational disruption

ProCheckUp needed to prove whether weaknesses translated into meaningful access while avoiding prolonged network poisoning, privileged account creation, persistence or actions that could interrupt banking operations. This required careful manual validation and clear stop conditions.

A repeat assessment rather than a blank-slate review

Several earlier issues had improved. The new assessment therefore needed to recognise progress while determining whether the remaining weaknesses still formed an end-to-end route from internal access towards identity and critical services.

Assessment Scope

The public case study generalises the original network names and technical identifiers. Testing concentrated on the following trust boundaries:

  • - Application network: business applications, infrastructure services, endpoints and routes towards identity or critical systems
  • - Core-banking network: directory services, servers and systems supporting sensitive financial operations and essential workflows
  • - Vendor-managed equipment: third-party-supported voice, print, network and specialist operational devices
  • - Network infrastructure: switches, routing, firewalls, segmentation, network access control and management protocols
  • - Identity and Windows security: Active Directory, IPv6, name resolution, SMB, credential protection and remote administration
  • - Embedded and peripheral devices: multifunction printers, address books, firmware, voice devices, default credentials and SNMP

Representative sampling was used where large groups of similar devices were present. One vendor-managed subnet was removed from scope during the test window. Potentially disruptive persistence and privileged account creation were intentionally avoided.

Solution

ProCheckUp combined broad network discovery with consultant-led exploitation and attack-path analysis. Automated tools established the extent of exposed services and software versions; manual validation determined which observations produced genuine access, identity or business impact.

The assessment followed four stages:

  • 1. Discover: enumerate hosts, services, versions, protocols, trust boundaries and device classes across the agreed estate.
  • 2. Validate: safely confirm default credentials, unauthenticated services, exposed applications, legacy protocols and bypassable network-access controls.
  • 3. Chain: test whether individual weaknesses could combine from device connection to identity relay, directory visibility, cross-zone movement and critical-service exposure.
  • 4. Prioritise: separate urgent compromise paths from lifecycle debt and translate evidence into immediate, engineering and governance actions.

Evidence quality remained central. Confirmed access, successful relays and mounted storage were reported as demonstrated. Findings based on detected versions were labelled accordingly and were not presented as proof that every associated vulnerability had been exploited.

Findings Overview

The 22 findings converged on four systemic themes: identity relay, unsupported technology, weak trust boundaries and inconsistent management of embedded or peripheral devices.

Critical — four findings

  • - IPv6 DNS takeover and authentication relay — CVSS 10.0
  • - Multiple obsolete operating systems — CVSS 10.0
  • - Critical network-security appliance vulnerabilities — CVSS 9.8
  • - Printer-fleet vulnerability exposure — CVSS 9.0

High — eleven findings

  • - Voice-device firmware and session vulnerabilities — CVSS 8.8
  • - Default credentials on internal devices — CVSS 8.6
  • - Multifunction-printer address-book credential exposure — CVSS 8.6
  • - Business-critical banking application exposed without authentication — CVSS 8.4
  • - NFS share freely mountable without authentication — CVSS 8.4
  • - Weak segregation between application and core-banking zones — CVSS 8.3
  • - Legacy and weak SSH configuration — CVSS 8.1
  • - SMBv1 and non-required SMB signing — CVSS 8.1
  • - Default read/write SNMP community strings — CVSS 7.5
  • - Weak TLS and SSL configuration — CVSS 7.5
  • - Sensitive data sent through cleartext protocols — CVSS 7.4

Medium and Low — seven findings

  • - IP forwarding enabled on non-routing hosts — CVSS 6.5
  • - Weak Remote Desktop configuration — CVSS 6.5
  • - Inconsistent protection of server secrets — CVSS 6.3
  • - LLMNR and NetBIOS name-resolution exposure — Medium
  • - Network access control bypass through static addressing and MAC spoofing — CVSS 5.9
  • - Anonymous FTP access — CVSS 5.3
  • - Environment and software-version disclosure — CVSS 3.3

Critical Findings

IPv6 DNS takeover and LDAP relay — Critical, CVSS 10.0

Windows clients accepted responses from an authorised rogue IPv6 DNS service. Authentication was then relayed successfully to LDAP, allowing ProCheckUp to export Active Directory information covering users, groups, computers, servers and descriptive metadata.

Recommendation: disable IPv6 and WPAD where not required; otherwise manage IPv6 deliberately. Enforce LDAP signing, SMB signing and Extended Protection, reduce or retire NTLM, and monitor DHCPv6, WPAD and relay-related anomalies.

Evidence boundary: the successful relay and directory extraction were confirmed. Creating a user, changing an ACL or maintaining the rogue service for longer was not attempted because doing so could have disrupted operations.

Unsupported operating systems — Critical, CVSS 10.0

Multiple server and workstation platforms were beyond normal vendor support. These systems no longer received the ordinary security fixes needed to address newly discovered vulnerabilities and some supported important network functions.

Recommendation: upgrade, migrate or decommission unsupported systems. Where immediate replacement is not possible, isolate them behind strict firewall rules, least-privilege access, monitored jump hosts and a time-bound retirement plan.

Critical network-security appliance vulnerabilities — Critical, CVSS 9.8

The assessment identified critical authentication-bypass and remote command-execution exposure affecting network-security infrastructure. A controlled detection script confirmed that an assessed appliance was exposed to the authentication-bypass condition.

Recommendation: apply vendor fixes urgently, restrict management services to dedicated trusted networks, remove unnecessary administrative exposure, review privileged accounts and logs, and investigate unexpected configuration or account changes.

Evidence boundary: vulnerability presence was confirmed; the public case study does not claim that ProCheckUp used it to obtain persistent super-administrator control.

Printer-fleet vulnerability exposure — Critical, CVSS 9.0

Printer models within the estate were associated with network-stack, buffer-overflow, remote-code-execution and denial-of-service vulnerabilities. Embedded devices can remain operational for many years and may not follow the same patch cycle as servers or endpoints.

Recommendation: maintain an authoritative printer inventory, update firmware, restrict management and printing protocols, segment devices from critical systems, remove unused services and include printers in vulnerability and lifecycle governance.

Evidence boundary: this finding was based on identified versions and affected product families. It does not claim that every associated CVE was exploited during testing.

High-Severity Findings

Business-critical application exposure — High, CVSS 8.4

An application supporting sensitive banking operations was accessible from the internal network without authentication or adequate access control. This created a direct route from an ordinary internal foothold to a high-value operational service.

Recommendation: place the application in a restricted network zone, allow access only through approved systems or jump hosts, require strong authentication and MFA, harden sessions, and monitor all access and administrative activity.

Unauthenticated NFS and weak cross-zone segregation — High, CVSS 8.4 and 8.3

ProCheckUp mounted an NFS share without authentication and listed its contents. Separately, systems in the core-banking zone, including directory services, were reachable from the application network. Together these weaknesses increased opportunities for data access and lateral movement.

Recommendation: restrict NFS exports to authorised hosts, enable root squashing, remove unnecessary write access and use authenticated NFS where appropriate. Enforce segmentation through firewalls, VLANs, ACLs and identity-aware NAC between endpoint, application, management, voice and core-system zones.

Default credentials, voice devices and printer address-book exposure — High, CVSS 8.8 to 8.6

Default credentials remained on multiple device classes. Vulnerable voice-device firmware weakened session and administrative controls, while a multifunction-printer address-book export exposed domain credential material with value beyond the device itself.

Recommendation: remove every default account or password, centralise device administration, rotate exposed credentials, update device firmware, restrict management access and review logs for prior unauthorised access.

Legacy management and file-sharing protocols — High, CVSS 8.1 to 7.4

SSH version 1, weak SSH algorithms, SMBv1, non-required SMB signing, default read/write SNMP strings, obsolete TLS configurations and cleartext HTTP, FTP, LDAP and Telnet reduced confidentiality and enabled interception, relay or device reconfiguration.

Recommendation: retire SSHv1 and SMBv1; require modern SSH, SMB signing and TLS 1.2 or later; migrate to HTTPS, SFTP, LDAPS and SSH; require SNMPv3 with strong authentication and privacy; and restrict all management services to approved sources.

Medium and Low Findings

The remaining issues materially increased the value of an established foothold:

  • - IP forwarding: selected hosts could route traffic and potentially bypass intended control points
  • - Remote Desktop: server validation and Network Level Authentication were not consistently enforced
  • - Server secrets: password hashes could be extracted from some servers but not others, showing inconsistent hardening
  • - LLMNR and NetBIOS: peer name resolution allowed hash-capture and relay conditions when DNS resolution failed
  • - Network access control: DHCP MAC allow-listing was bypassed with static addressing and MAC spoofing
  • - Anonymous FTP: services accepted connections without a named authenticated user
  • - Information disclosure: software and device banners reduced attacker reconnaissance effort

Network access control evidence: assigning a valid static address allowed communication without receiving a DHCP lease, and presenting an authorised MAC identity caused DHCP to issue an address. This confirmed that MAC filtering alone did not establish trustworthy device identity.

Credential evidence boundary: previously authorised test material was used to validate whether selected servers still allowed secrets extraction. The current window did not establish a new domain-administrator compromise and the public case study does not claim one.

Authorised Attack Path

The following sequence explains how the demonstrated findings could combine. Confirmed stages are separated from potential downstream impact:

  • 1. Connect an unauthorised device — confirmed: an internal network point was available to the authorised tester.
  • 2. Bypass device admission — confirmed: static addressing and MAC spoofing defeated the DHCP-based allow-list.
  • 3. Establish internal reachability — confirmed: the test device communicated with internal hosts and services.
  • 4. Impersonate IPv6 DNS — confirmed: Windows client name-resolution traffic was directed towards the rogue service.
  • 5. Relay authentication to LDAP — confirmed: an authentication attempt was accepted and relayed successfully.
  • 6. Enumerate identity and reach critical zones — confirmed: directory information was exported and weak segmentation exposed core services, a critical application and NFS data.
  • 7. Escalate to wider banking impact — potential: privileged access, data compromise, fraud or operational disruption could follow, but these actions were not executed.

This is an authorised risk model, not evidence of a completed real-world compromise. ProCheckUp did not create a privileged account, establish persistence, alter financial data or disrupt banking operations.

Control Improvements and Assessment Boundaries

Positive improvements observed since the earlier review

  • - A principal domain controller had moved to a supported server platform
  • - Account-lockout policy was present
  • - Printers used a dedicated service account rather than a domain-administrator identity
  • - Password handling for launching services had improved
  • - Basic network access control had been introduced
  • - Monitoring and alerting capability had been expanded

Why material risk remained

  • - MAC-based admission did not authenticate the device or user
  • - Unsupported systems and unpatched embedded equipment remained
  • - Identity and name-resolution protocols still enabled relay attacks
  • - Application and core-banking zones were not adequately separated
  • - Critical applications and file shares lacked effective authentication
  • - Hardening was inconsistent between apparently similar systems

Assessment boundaries

  • - Representative sampling was used across large groups of similar devices
  • - One vendor-managed subnet was removed from scope during the test window
  • - Potentially disruptive persistence, privileged account creation and prolonged poisoning were not performed
  • - Version-correlated device findings do not imply that every associated CVE was exploited
  • - The source report does not establish that all recommendations were subsequently implemented or independently retested

Outcome

The engagement gave the bank a comparative view of progress and a practical route towards stronger internal resilience. It showed where earlier remediation had worked, where control depth remained inconsistent and which combinations created the greatest business risk.

Rather than treating every finding as equivalent, ProCheckUp prioritised closure of the demonstrated compromise route: device admission, IPv6 and authentication relay, identity protection, application exposure, segmentation and critical-service access. Lower-value banner and protocol clean-up could then follow within a structured lifecycle programme.

The assessment also showed that improvement was achievable. Several earlier weaknesses had been addressed. The remaining results demonstrated that consistent enforcement across the whole estate was now more important than isolated hardening of individual systems.

Publication boundary: this case study does not state that the complete remediation programme was subsequently implemented or independently retested.

Remediation Priorities

Immediate containment

  • - Disable or securely manage IPv6 and WPAD; enforce LDAP and SMB signing
  • - Isolate the critical banking application and require strong authentication
  • - Restrict unauthenticated NFS and remove unnecessary write access
  • - Patch critical security appliances and vulnerable embedded devices
  • - Remove default credentials and rotate exposed account material
  • - Replace cleartext management and authentication protocols
  • - Upgrade, decommission or tightly isolate unsupported operating systems

Engineering hardening

  • - Implement 802.1X and certificate-based user and device authentication
  • - Add switch-port security, DHCP snooping and Dynamic ARP Inspection
  • - Separate endpoint, application, management, voice and core-system zones
  • - Require SMBv2 or later, SMB signing, modern SSH and TLS 1.2 or later
  • - Deploy LSA protection, Credential Guard and consistently hardened RDP
  • - Retire LLMNR, NetBIOS name resolution and anonymous FTP where unnecessary

Sustained infrastructure governance

  • - Maintain authoritative asset, firmware, operating-system and ownership inventories
  • - Apply risk-based patch and retirement service levels across every device class
  • - Continuously monitor DHCPv6, DNS, relay and rogue-device anomalies
  • - Review service accounts, privileged access and secret protection consistently
  • - Validate segmentation, NAC and management-plane restrictions regularly
  • - Retest demonstrated findings after remediation

The Core Security Lesson

Internal access must still be treated as untrusted.

A cable connection, compromised endpoint or copied MAC address should not inherit a route to directory information, critical applications and core-banking services. Strong internal assurance requires verified device identity, protected authentication, consistent hardening, strict segmentation and modern technology lifecycle management.

The correct question is not simply:

“Can an unauthorised device obtain a DHCP address?”

It is:

“Can any internal foothold reach identity and critical services before controls contain it?”

How ProCheckUp Helps

ProCheckUp’s Internal Infrastructure Penetration Testing service assesses the complete route from network connection to business impact. Support can include:

  • - Onsite and remote internal network penetration testing
  • - Insider-threat and unauthorised-device simulation
  • - Active Directory, IPv6, NTLM, LDAP and SMB attack-path testing
  • - Network segmentation and core-system reachability validation
  • - Network access control and 802.1X assessment
  • - Server, endpoint, printer, voice and embedded-device testing
  • - Default-credential and management-plane review
  • - Legacy protocol, cryptography and cleartext-traffic assessment
  • - Patch, firmware and unsupported-platform exposure analysis
  • - Prioritised remediation and verification testing

Related services include Infrastructure Testing, Penetration Testing and scoped security assurance.

Conclusion

This engagement demonstrated why internal trust must be earned through identity, protocol and segmentation controls rather than inferred from network location. The decisive risks were not isolated scanner findings: they were the interaction between bypassable device admission, authentication relay, unsupported technology, unauthenticated services, weak segmentation and inconsistent hardening.

By closing the demonstrated attack path first, then modernising protocols, platforms, embedded devices and lifecycle governance, banks and other regulated organisations can materially reduce the likelihood that one internal connection becomes a route to identity and critical operations.

To discuss an Internal Infrastructure Penetration Test, segmentation review or wider adversary simulation, contact ProCheckUp.

Need Help?

If you have any questions about cyber security or would like a free consultation, don't hesitate to give us a call!

Our Services

Keep up to date!

Subscribe to our newsletter. Keep up to date with cyber security.


For More Information Please Contact Us

Smiling Person

ACCREDITATIONS