Live data from Hacker News

Web Application Penetration Testing Cheat Sheet

jdow.io

11–20 of 40 posts

Re: Web Application Penetration Testing Cheat Sheet

#11
Can somebody tell me as to what pen testers typically earns?

I once talked to a firm doing pen testing and the figures they paid were the same as any other firm would pay a midlevel developer working in a regular software dept in a corporation in that city.

Assuming pen testing requires a skill level a notch or two above the 'average' developer, I would have normally assumed that ideally they would be paid significantly better.

Re: Web Application Penetration Testing Cheat Sheet

#12

Can somebody tell me as to what pen testers typically earns? I once talked to a firm doing pen testing and the figures they paid were the same as any other firm would pay a midlevel developer working in a regular software dept in a corporation in that city. Assuming pen testing requires a skill level a notch or two above the 'average' developer, I would have normally assumed that ideally they would be paid significan…

I get the idea that most pen testers are entry-level and spend their time doing standard scanning and looking for standardized types of vulnerabilities using pre-built tools and techniques. The ones who can build those tools and come up with novel attacks against well-protected targets are the top of the heap.

What is probably scary is just how many commercial sites can be compromised by those standard well-known techniques.

Re: Web Application Penetration Testing Cheat Sheet

#13

Can somebody tell me as to what pen testers typically earns? I once talked to a firm doing pen testing and the figures they paid were the same as any other firm would pay a midlevel developer working in a regular software dept in a corporation in that city. Assuming pen testing requires a skill level a notch or two above the 'average' developer, I would have normally assumed that ideally they would be paid significan…

I think it's about on par with what developers earn for the same skill bracket and location. As a pentester, I don't think it's necessarily about having _more_ skill than developers, it's just a different set of skills.

Re: Web Application Penetration Testing Cheat Sheet

#15
post #6
post #3

Nice, just started reading and looking forward to it, but also I'm loving this blog setup, particulary how clean the "warning" sections are. Is it a custom setup?

It seems to be the default Jekyll theme: https://jekyllrb.com/docs/home/

Nope, that would be minima: https://github.com/jekyll/minima

Minima's the theme you get when you run "jekyll new".

This is just a theme that Jekyll uses. I'm not quite sure it even has a name.

Re: Web Application Penetration Testing Cheat Sheet

#17

Are there tools that automatically do all, or most, of this and present the data in a nice GUI?

Yes.

People running these tools are so common that "automated reports" are routinely excluded from public bug bounty programs. The ratio of false findings to true findings is very high.

Re: Web Application Penetration Testing Cheat Sheet

#18
I was using sqlmap once and was genuinely surprised how good UI it has. It automatically does so much guesswork and only asks highly important questions, but at the same time it never gets in the way. Also, it does few other things beside just SQL injection, and it surprisingly gave me shell access when I was not even looking for it.

Re: Web Application Penetration Testing Cheat Sheet

#19

Can somebody tell me as to what pen testers typically earns? I once talked to a firm doing pen testing and the figures they paid were the same as any other firm would pay a midlevel developer working in a regular software dept in a corporation in that city. Assuming pen testing requires a skill level a notch or two above the 'average' developer, I would have normally assumed that ideally they would be paid significan…

Top tier bug bounty hunters can make hundreds of thousands per year on Hackerone/Bugcrowd/Synack.

Re: Web Application Penetration Testing Cheat Sheet

#20

Can somebody tell me as to what pen testers typically earns? I once talked to a firm doing pen testing and the figures they paid were the same as any other firm would pay a midlevel developer working in a regular software dept in a corporation in that city. Assuming pen testing requires a skill level a notch or two above the 'average' developer, I would have normally assumed that ideally they would be paid significan…

Top tier bug bounty hunters can make hundreds of thousands per year on Hackerone/Bugcrowd/Synack.

How many hundreds are we talking?
Post reply on HN