Performed manual web application security testing against one of Xero’s ancillary applications using Portswigger Burp and recovered some unreported issues.
• Demonstrated what an attacker would do when gathering information about Xero from publically available resources.
• Performed scanning on Zero’s internal, semi-public and public networks to look for running devices, operating systems and host information.
• Performed scanning on networks using Nessus Vulnerability Scanner and submitted an executive summary that outlined the details of any issues discovered.