The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.
Penetration testing and low-cost freelancing
71–76 of 76 posts
Re: Penetration testing and low-cost freelancing
#72As a thought experiment, I think the best course of action for these freelance pen testers - assuming they incur no actual liabilities for being wrong - is to simply declare everything they test "secure" without putting any actual effort into it at all. If they can manage to do this at any scale whatsoever, there is basically no downside, because there's a huge disconnect between the impact of a false negative (site…
A proper pentest includes manual labour (such as the mentioned examples). It also includes a lot of documentation in the report. For example, recon data. They could also include we checked X for Y but did not found any issues. Nothing is 100% secure, and if you don't find anything after extensive manual testing it is, well, going to be a boring report, because you still have to document everything. It also feels like a failure (which is why the honeypot was a little bit mean, though clever as well given goal of post).
CEH is a joke btw. No serious pentester puts that on their resume. Its a waste of time to get thst certificate. OSCP is the gold standard.
In short, you pay peanuts you get monkeys and CEH is a red flag. OSCP is a green flag.
Re: Penetration testing and low-cost freelancing
#73The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.
This is not always true. I’ve seen a ton of costly engagements produce super low quality deliverables that yielded no real value except for a checkbox being filled.
Re: Penetration testing and low-cost freelancing
#74Earlier quoted context omitted.
Some SSH honeypots accept more than one password for root. So, if 'letmein' and 'changeme' get you a root shell, it's probably a honeypot... but it could be a very broken PAM config as well (I have seen this firsthand).
PAM is one utter freaking nightmare to set up if one wants to stray from the distro defaults. Actually I'm astonished no one has dared to try and develop an alternative... god knows it's about time.
Re: Penetration testing and low-cost freelancing
#75I’m curious which freelancing sites you got these from
Re: Penetration testing and low-cost freelancing
#76Clickbait title. I refuse to click.
The title reflects the content. He hired 7 pentesters and shows the results. Why comment if you don't even want to read the article?
"This one weird X" is a common clickbait pattern, and indeed, in this case, it is misleading: the article's descriptions of the purposely-introduced "weird" vulnerabilities aren't useful, only the freelance test results are.