Live data from Hacker News

The World's Worst Penetration Test Report by #ScumbagPenTester

it.toolbox.com

1–10 of 26 posts

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#3
post #2

where do you even find people so unreputable? This seems beyond unreasonable to the point of it being illegal.

Any number of countries in Africa, Asia, Europe, North America, and South America. All you need is to operate from a country that doesn't honor the laws of your target's country.

This kind of fraud happens with outsourced manufacturing in China all the time. Not limited to china but it's just the first thing that came to my mind.

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#4
> Microsoft IIS susceptible to CVE-XXXXXXXX. Recommend applying accordingly patch.

> Another almost good finding - but according to the appendix, this host is a RHEL 5.x box. Those sysadmins - finding ways to run IIS on linux!! Brilliant!

I used to see crap like this all the time coming out of PCI compliance audits. The hosts I dealt with ran Apache on RHEL, too. We'd point this out, and they'd "accept" that "fix."

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#5
This is the world's worst writeup of the world's worst penetration test report.

First, this article is on some linkbait site and it gets posted to HN.

Second, the author complains that these kinds of outfits haven't been "weeded out" of the industry. Anyone with half a mind in the security industry knows that it is filled with charlatans and snake oil. That the author finds this surprising seems to indicate they're a bit green. Nobody's been weeded out from existence. Thus, a little caution and common sense is required.

I suspect the author's associate probably did a Google search for "pentester" and stumbled upon this outfit. Or worse, he read the stunning Google reviews for this outfit.

Also, as a US company, don't use an Indian company for a task so sensitive, and where it's vital that language be precise. Maybe that's politically-incorrect, but its the truth. If you're an Indian company, by all means ignore this advice.

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#7
If this is a baseline for "very bad" penetration testing, it makes me think I could start up an "almost competent" low-end penetration-testing business just by blindly following a checklist found on the internet, as long as I used a checklist for the right operating system and proof-read the final report.

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#8
post #4

> Microsoft IIS susceptible to CVE-XXXXXXXX. Recommend applying accordingly patch. > Another almost good finding - but according to the appendix, this host is a RHEL 5.x box. Those sysadmins - finding ways to run IIS on linux!! Brilliant! I used to see crap like this all the time coming out of PCI compliance audits. The hosts I dealt with ran Apache on RHEL, too. We'd point this out, and they'd "accept" that "fix."

I've seen similar to this with our pen-test firm (who apparently do pen-tests for the UK NHS) - we're a C#/ASP.NET shop, running on Windows servers and they know this.

For some reason when I examine our logs after each test I see attempts at access to /usr etc.

It does make me wonder if all so called pen-test companies are just one massive scam.

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#9
Sadly, relative to what I've seen, the examples here really aren't that bad. There are plenty of outfits based right here in the US who will happily sell you the output of a default scan from an outdated version of Nessus.

Also, you've not seen cut-n-paste, search-and-replace garbage until you've had to sift through the mountain of responses to a public sector RFP.

My best theory is that there are a large number of companies which simply shotgun shoveled together lowball responses to every posting. The lowball number virtually guarantees consideration and people who either don't really understand what they're procuring or don't actually read the responses let the stuff slip through.

I always made a point of requesting that the companies which submitted crap like that be banned from future solicitations - it never worked.

Re: The World's Worst Penetration Test Report by #ScumbagPenTester

#10
post #8
post #4

> Microsoft IIS susceptible to CVE-XXXXXXXX. Recommend applying accordingly patch. > Another almost good finding - but according to the appendix, this host is a RHEL 5.x box. Those sysadmins - finding ways to run IIS on linux!! Brilliant! I used to see crap like this all the time coming out of PCI compliance audits. The hosts I dealt with ran Apache on RHEL, too. We'd point this out, and they'd "accept" that "fix."

I've seen similar to this with our pen-test firm (who apparently do pen-tests for the UK NHS) - we're a C#/ASP.NET shop, running on Windows servers and they know this. For some reason when I examine our logs after each test I see attempts at access to /usr etc. It does make me wonder if all so called pen-test companies are just one massive scam.

"We got local file inclusion but cannot read /etc/passwd. No idea what went wrong..."
Post reply on HN