Live data from Hacker News

Penetration testing and low-cost freelancing

sophron.github.io

21–30 of 76 posts

Re: Penetration testing and low-cost freelancing

#21

"While the cost of penetration testing can be pretty high (typically between $1,000 and $100,000+)," I've always been curious about costs for real pentesting. 1-100k is a HUGE range, that can't mean the range in cost for the same project can be that big, can it? What's it cost to hire someone to run a decent set of tests on a Rails app, for instance? Could I really see that big of a range? Would I get way better resu…

You will find exponentially less vulnerabilities the more money you spend. How much you should spend depends on how big the damage could be in case of a breach.

Re: Penetration testing and low-cost freelancing

#23

People are paying pentesters because their payer’s policy asks them to. Of course there will be a huge market for someone with an alleged certification to run automated tools, the value is in the box checking and report generation, not the bespoke broken website fixing.

Obviously this is a bit of a reaching statement, some organizations understand the legal, career, and regulatory risk and proactively do it.

In every org I've sat down with the head to explain those risks, I can see how it can be made priority and budget.

Re: Penetration testing and low-cost freelancing

#24
The problem that strikes me here (as a professional pentester) is that these vulnerabilities are so pathological. There is no realistic series of errors that would lead you to really design an app with hardcoded sqli looking credentials or somehow return a cookie with a malformed header, let alone one that somehow automatically authenticated the user. I am extremely onboard with the idea that pentesting as a whole has a lot of scanner jockeys (and a lot of my current work is finding people who aren't.) But you're not testing for vulnerabilities that would actually show up in the real world, and it is hurting your analysis.

Re: Penetration testing and low-cost freelancing

#25

"While the cost of penetration testing can be pretty high (typically between $1,000 and $100,000+)," I've always been curious about costs for real pentesting. 1-100k is a HUGE range, that can't mean the range in cost for the same project can be that big, can it? What's it cost to hire someone to run a decent set of tests on a Rails app, for instance? Could I really see that big of a range? Would I get way better resu…

"A rails app" could be a rails default build, or Github.

You should get significantly better results the more one pays - because of the human element.

For example, $1k gets you a basic Nessus/Nmap (basic vulnerability/mapping) scans, maybe SQL vuln, with automated reporting. More gets you architecture, infrastructure, penetration, white/black scenarios, risk assessment, external organization liability, code repo, data, compliance, and regulatory footing. Those can surpass $100k easily.

Re: Penetration testing and low-cost freelancing

#27
Now a real interesting article would be what appsec service would have the highest impact for $100? Obviously not pentest. Code review? Architecture analysis? At $100 none of it would be deep of course. I could find a lot more stuff of interest in 2 hours of code review compared to pentesting.

Re: Penetration testing and low-cost freelancing

#29
> What is surprising is the number of people purchasing these security services as well as the number of positive reviews. An incomplete security testing methodology results in a false sense of security for the assessed systems.

The same is happening in the "smart contract audit" space. The results of the audit do not matter to the audience that wants to see the checkbox of "audit".

You can currently make a lot of money undercutting other auditors providing these audits.

The person requesting the audit is making multiple orders of magnitude more money by having the audit.

Post reply on HN