Live data from Hacker News

Penetration testing and low-cost freelancing

sophron.github.io

11–20 of 76 posts

Re: Penetration testing and low-cost freelancing

#14
post #2

Number 3 wil surprise you!

if anything, the number 5 should be the surprising one

I have VMs specifically for running garbage that I find/need to but I don't trust. These have 0 personal information and gets wiped to a clean state afterwards.

Re: Penetration testing and low-cost freelancing

#15
This isn't really comparing the results to other pentests, so I have a hard time seeing the use of this. I think almost any pentest will miss some/many security issues.

And these issues look more like CTF style issues than real world security issues. If you're not thinking about the challenge in the right way, it is probably harder to see the vulnerabilities.

Re: Penetration testing and low-cost freelancing

#17
I'm trying to imagine being a customer for this kind of service. When would I be satisfied with a pen testing service?

If I'm not familiar with pentesting methodologies, my only metric of satisfaction would be the pen tester's reputation i.e., if a well-reviewed pentester says my site is OK, then maybe my site is safe.

Re: Penetration testing and low-cost freelancing

#20

The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.

I agree with you - yet there is also a philosophy that some organizations take which is to intentionally hire quite subpar 'certified' practitioners who themselves can be duped or walked past issues to provide 'clean reports' to upper management, even if false.
Post reply on HN