Ask a Penetration Tester Anything

What does it take to become certified as a CEH and what are the salary ranges and the job market like?
 
Can you do automated penetration testing as part of continuous integration?

Hi Glingfram

Yes, we can. However requests for this are less common due to the availability of some really easy to use tools such as nessus, nexpose, qualys and openvas
 
Most common exploit you find?

Not SQL inject protecting cookies seems quite common with me.

SQL Injection is actually less common these days due to the various frameworks moving towards a "secure by default" out of the box configuration.

The most common things you will find on websites are SSL certificate issues, weak password policies and session management issues.

But these days the quickest way into most systems/networks is via a targeted phishing attack.
 
Do you guys buy black market zero exploits or do you just use publicly available exploits for meterpreter?
 
But these days the quickest way into most systems/networks is via a targeted phishing attack.

Well the user is always the weakest link.


Do you guys buy black market zero exploits or do you just use publicly available exploits for meterpreter?

I would imagine the usual, kali, metasploit, nmap, lots of dorks to automate known exploits which we share.
 
Would have expected IDA...

Describe the average client. Size, industry etc. Obviously it varies but humour me.

IDA is another one we use for malware reverse engineering.

Mostly JSE top 100 companies, various industries such as telecoms, financial sector and retail.
 
Do you guys buy black market zero exploits or do you just use publicly available exploits for meterpreter?

Hey ghoti

Many of our guys research a specific technology to find zero day exploits which we then share with the vendor and publish.
 
I would be keen to know the average junior position salary for penetration testing...?
 
How hard is it to resist the temptation of some light vandalisation once you are in?
 
Top
Sign up to the MyBroadband newsletter
X