Note how their e-mail server claims to be "http://ccn-cert.es ", but its IP address (213.192.250.68) had no reverse DNS set (unknown). This is a big no-no; my server had a permissive config at the time, but many others would've rejected this message (as mine would today).
-
-
So let's recap: 5 year old webmail, 6 year old e-mail server, >2 year old PGP with an arbitrary code exec CVE. The key itself? The userid was "CCN-CERT.PublicKey <CCN-CERT.PublicKey.Depart@CCN.es>", which does not match the sender of the e-mail either.
Show this thread -
Not that this was going to go anywhere by now, but I replied with inline PGP, and sent them my phone number to see what their story was. I didn't hear back for two weeks. Apparently they had gone on vacation.
Show this thread -
At least they managed to sign their message when they finally replied? Still using attachments though. I figured this wasn't worth wasting any more of my time on by then, didn't reply and never heard back.
Show this thread -
So there you go, that was my recruiting experience from a branch of Spain's NSA. Not exactly a shining example of competence.
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.