Snowpick: Open-source ServiceNow Exposure Scanner
Brief
An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back.
Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests. The firm published the results along with the Go tool it used, Snowpick.
The post Snowpick: Open-source ServiceNow Exposure Scanner appeared first on Linux Today .
