Penetration testing and low-cost freelancing
11–20 of 76 posts
So how would someone know they have connected to a honeypot? Presumably detecting this sort of thing is deliberately difficult, otherwise there isn't much point of the honeypot?
Re: Penetration testing and low-cost freelancing
#12This comes down to the fact that penetration testing has a high false-negative rate. There's no way for a customer to really evaluate what a mostly empty report means, if there actually are no bugs, or the penetration tester missed them/did a poor job.
Re: Penetration testing and low-cost freelancing
#13For those prices (except maybe the 400$) I don't think anyone is going to perform manual actions or invest more than a couple of hours.
Re: Penetration testing and low-cost freelancing
#14Re: Penetration testing and low-cost freelancing
#15This isn't really comparing the results to other pentests, so I have a hard time seeing the use of this.
I think almost any pentest will miss some/many security issues.
And these issues look more like CTF style issues than real world security issues. If you're not thinking about the challenge in the right way, it is probably harder to see the vulnerabilities.
Re: Penetration testing and low-cost freelancing
#16The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.
Re: Penetration testing and low-cost freelancing
#17I'm trying to imagine being a customer for this kind of service. When would I be satisfied with a pen testing service?
If I'm not familiar with pentesting methodologies, my only metric of satisfaction would be the pen tester's reputation i.e., if a well-reviewed pentester says my site is OK, then maybe my site is safe.
Re: Penetration testing and low-cost freelancing
#18What they didn't test is whether higher cost services would find the vulnerabilities.
Re: Penetration testing and low-cost freelancing
#19Clickbait title. I refuse to click.
Re: Penetration testing and low-cost freelancing
#20The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.
I agree with you - yet there is also a philosophy that some organizations take which is to intentionally hire quite subpar 'certified' practitioners who themselves can be duped or walked past issues to provide 'clean reports' to upper management, even if false.