Live data from Hacker News

Penetration testing and low-cost freelancing

sophron.github.io

71–76 of 76 posts

Re: Penetration testing and low-cost freelancing

#71

The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.

This is not always true. I’ve seen a ton of costly engagements produce super low quality deliverables that yielded no real value except for a checkbox being filled.

Re: Penetration testing and low-cost freelancing

#72

As a thought experiment, I think the best course of action for these freelance pen testers - assuming they incur no actual liabilities for being wrong - is to simply declare everything they test "secure" without putting any actual effort into it at all. If they can manage to do this at any scale whatsoever, there is basically no downside, because there's a huge disconnect between the impact of a false negative (site…

You can't expect a manual pentest for €35 or anything near that ballpark.

A proper pentest includes manual labour (such as the mentioned examples). It also includes a lot of documentation in the report. For example, recon data. They could also include we checked X for Y but did not found any issues. Nothing is 100% secure, and if you don't find anything after extensive manual testing it is, well, going to be a boring report, because you still have to document everything. It also feels like a failure (which is why the honeypot was a little bit mean, though clever as well given goal of post).

CEH is a joke btw. No serious pentester puts that on their resume. Its a waste of time to get thst certificate. OSCP is the gold standard.

In short, you pay peanuts you get monkeys and CEH is a red flag. OSCP is a green flag.

Re: Penetration testing and low-cost freelancing

#73

The only thing this article proves yet again is: if you pay peanuts you get monkeys. I mean, 100 dollar is maybe enough for 2 hours of a freelancers time. But I do not think that is enough time to find both issues and scan the server.

This is not always true. I’ve seen a ton of costly engagements produce super low quality deliverables that yielded no real value except for a checkbox being filled.

Right, but the cheap ones are almost guaranteed to be bad.

Re: Penetration testing and low-cost freelancing

#74
post #48

Earlier quoted context omitted.

Some SSH honeypots accept more than one password for root. So, if 'letmein' and 'changeme' get you a root shell, it's probably a honeypot... but it could be a very broken PAM config as well (I have seen this firsthand).

PAM is one utter freaking nightmare to set up if one wants to stray from the distro defaults. Actually I'm astonished no one has dared to try and develop an alternative... god knows it's about time.

There are alternatives. Last time I checked OpenBSD uses BSD_Auth; not PAM.

Re: Penetration testing and low-cost freelancing

#76
post #26

Clickbait title. I refuse to click.

The title reflects the content. He hired 7 pentesters and shows the results. Why comment if you don't even want to read the article?

The title of the HN submission was changed. It used to be the article's subtitle, "How I Hired 7 Freelancers to Exploit this Weird Vulnerability".

"This one weird X" is a common clickbait pattern, and indeed, in this case, it is misleading: the article's descriptions of the purposely-introduced "weird" vulnerabilities aren't useful, only the freelance test results are.

Post reply on HN