ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Pentest - Who would you recommend?

    IT Discussion
    8
    48
    4.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jimmy9008
      last edited by

      Hey folks,

      We are based in London and are interested in having a pentest performed. Don't mind where the person is based as its testing the vulnerability of our sites and services externally anyway.

      Who would you recommend?

      I am not looking for an MSP or reseller or a VAR. We don't want somebody that is only looking to do a few 'checks' and then suggest we entirely swap out our firewall, routers, switches, access points etc as they are actually resellers looking to line their pockets with their own 'solutions'.

      What we are looking for is for somebody to look at our attack vector from outside and point at what could be improved. We would be paying for that report. Any work done, if any, would be done by a similarly skilled consultant in that specific area or internally if possible.

      So, thoughts? This is not a job posting, this is a discussion to see who the community has used before and would recommend.

      Best,
      Jim

      1 Reply Last reply Reply Quote 2
      • C
        Carnival Boy
        last edited by

        I've never actually used them, but I've been to a couple of seminars by Sec-1 which were awesome. I really liked them. If I was going to do a pentest, I would want to use them. I recommend you go to one of their seminars as they're free and pretty intense and educational, and not salesy at all.

        1 Reply Last reply Reply Quote 1
        • IRJI
          IRJ
          last edited by

          Have you had an assessment before?

          Are you in an industry that has requirements like HIPAA, SOX, GLBA, etc?

          Roughly how big is the company?

          What is the exact scope of work? Are you really looking for a pen test or a security audit?

          All these should factor in to who you choose for you pentest.

          J 1 Reply Last reply Reply Quote 1
          • Deleted74295D
            Deleted74295 Banned
            last edited by

            I am clearly biased but I've gotta throw my 2 cents in here.

            https://darait.co.uk/files/darait-samplesecurityaudit-feb-2017.pdf

            What you receive entirely depends on the scope, for the audit above they wanted a zero scanning check to see what their external IT provider missed out after a breach which cost quite a bit of money. The external provider left out a lot even after they got told this was happening.

            Might be worth us having a chat.

            J 1 Reply Last reply Reply Quote 2
            • J
              Jimmy9008 @IRJ
              last edited by Jimmy9008

              @IRJ said in Pentest - Who would you recommend?:

              Have you had an assessment before?

              Are you in an industry that has requirements like HIPAA, SOX, GLBA, etc?

              Roughly how big is the company?

              What is the exact scope of work? Are you really looking for a pen test or a security audit?

              All these should factor in to who you choose for you pentest.

              No previous assessment.

              No industry requirements.

              25 -35 employees. Thousands of customers.

              Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

              Deleted74295D IRJI 2 Replies Last reply Reply Quote 1
              • J
                Jimmy9008 @Deleted74295
                last edited by Jimmy9008

                @Breffni-Potter said in Pentest - Who would you recommend?:

                I am clearly biased but I've gotta throw my 2 cents in here.

                https://darait.co.uk/files/darait-samplesecurityaudit-feb-2017.pdf

                What you receive entirely depends on the scope, for the audit above they wanted a zero scanning check to see what their external IT provider missed out after a breach which cost quite a bit of money. The external provider left out a lot even after they got told this was happening.

                Might be worth us having a chat.

                I've just read the report. Looks interesting, but not what we are after. That report looks more like in response to a breach.

                The brief would be... xyz is our company name. What can you do to us, of course, without actually doing the end attack. Example: We scanned for open ports on 195.40.15.81, xyz was open and is RDP. We tried brute force and got in on 3389 using non admin account. Once on, we were able to run xyz... (for an example of course, but based on far more advanced knowledge in to security and what an outside person could do than I know).

                1 Reply Last reply Reply Quote 0
                • Deleted74295D
                  Deleted74295 Banned
                  last edited by Deleted74295

                  @Carnival-Boy The only issue with sec-1 is they are a Claranet company. Claranet...their culture is really poor, they've kept making mistakes on ISP projects, support failures and for one client, Claranet actually held their service to ransom by switching off the connection before a migration to a competitor, the client buckled and re-signed for 2 years and within 10 minutes the service was back up.

                  Sec-1 might just be owned by Claranet and they are fantastic on their own but its a bit like LogMeIn owning LastPass, LastPass is great, LogMeIn, not so much.

                  @Jimmy9008 - Yep, it was a response to a breach. A specific requirement was zero pen-test but all other reports are similar, we looked here, tried this, found this, fix it this way.

                  C scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • Deleted74295D
                    Deleted74295 Banned @Jimmy9008
                    last edited by

                    @Jimmy9008 said

                    Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

                    Challenge accepted.

                    J 1 Reply Last reply Reply Quote 1
                    • J
                      Jimmy9008 @Deleted74295
                      last edited by

                      @Breffni-Potter said in Pentest - Who would you recommend?:

                      @Jimmy9008 said

                      Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

                      Challenge accepted.

                      Lol, but at what cost £££ 😛

                      Deleted74295D 1 Reply Last reply Reply Quote 0
                      • IRJI
                        IRJ @Jimmy9008
                        last edited by

                        @Jimmy9008 said in Pentest - Who would you recommend?:

                        @IRJ said in Pentest - Who would you recommend?:

                        Have you had an assessment before?

                        Are you in an industry that has requirements like HIPAA, SOX, GLBA, etc?

                        Roughly how big is the company?

                        What is the exact scope of work? Are you really looking for a pen test or a security audit?

                        All these should factor in to who you choose for you pentest.

                        No previous assessment.

                        No industry requirements.

                        25 -35 employees. Thousands of customers.

                        Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

                        You definitely don't want a pen test, you need a security assessment. There will be plenty of things to fix, and after securing the network then you could do a pen test the following year.

                        C 1 Reply Last reply Reply Quote 1
                        • Deleted74295D
                          Deleted74295 Banned @Jimmy9008
                          last edited by

                          @Jimmy9008 said in Pentest - Who would you recommend?:

                          @Breffni-Potter said in Pentest - Who would you recommend?:

                          @Jimmy9008 said

                          Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

                          Challenge accepted.

                          Lol, but at what cost £££ 😛

                          The fastest way to get the best pentest in the world, put out a bounty. Same way the big boys do it. If you get every type of hacker trying to crack your network for a prize, you can bet you'll find out if its secure.

                          This is a big problem with pen tests with many companies, how imaginative and motivated is the attacker?

                          J 1 Reply Last reply Reply Quote 3
                          • ObsolesceO
                            Obsolesce
                            last edited by

                            I love the Metasploit framework and also like Armitage on top of that sometimes.

                            1 Reply Last reply Reply Quote 0
                            • J
                              Jimmy9008 @Deleted74295
                              last edited by

                              @Breffni-Potter said in Pentest - Who would you recommend?:

                              @Jimmy9008 said in Pentest - Who would you recommend?:

                              @Breffni-Potter said in Pentest - Who would you recommend?:

                              @Jimmy9008 said

                              Pentest. You get our company name, that is all. Can you get in? Could you almost get in? What could/did you change? etc.

                              Challenge accepted.

                              Lol, but at what cost £££ 😛

                              The fastest way to get the best pentest in the world, put out a bounty. Same way the big boys do it. If you get every type of hacker trying to crack your network for a prize, you can bet you'll find out if its secure.

                              This is a big problem with pen tests with many companies, how imaginative and motivated is the attacker?

                              Yeah, I get what you are saying, but i'd prefer to avoid challenging those that had no interest in the company, with interest, to try to 'get the goodies'. Hence asking if anybody has specific good history with any particular person...

                              1 Reply Last reply Reply Quote 0
                              • C
                                Carnival Boy @Deleted74295
                                last edited by

                                @Breffni-Potter said in Pentest - Who would you recommend?:

                                @Carnival-Boy The only issue with sec-1 is they are a Claranet company. Claranet...

                                They only bought them 3 weeks ago! But, yeah, one to keep an eye on, for sure.

                                Deleted74295D 1 Reply Last reply Reply Quote 0
                                • Deleted74295D
                                  Deleted74295 Banned @Carnival Boy
                                  last edited by

                                  @Carnival-Boy said in Pentest - Who would you recommend?:

                                  @Breffni-Potter said in Pentest - Who would you recommend?:

                                  @Carnival-Boy The only issue with sec-1 is they are a Claranet company. Claranet...

                                  They only bought them 3 weeks ago! But, yeah, one to keep an eye on, for sure.

                                  Everyone knows BT are awful, Claranet manage to beat BT at being bad for double the money.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    Carnival Boy @IRJ
                                    last edited by

                                    @IRJ said in Pentest - Who would you recommend?:

                                    You definitely don't want a pen test, you need a security assessment. There will be plenty of things to fix, and after securing the network then you could do a pen test the following year.

                                    Same thing. What do you think an assessment will do that a pentester won't (and vice versa)?

                                    IRJI scottalanmillerS 2 Replies Last reply Reply Quote 1
                                    • IRJI
                                      IRJ @Carnival Boy
                                      last edited by

                                      @Carnival-Boy said in Pentest - Who would you recommend?:

                                      @IRJ said in Pentest - Who would you recommend?:

                                      You definitely don't want a pen test, you need a security assessment. There will be plenty of things to fix, and after securing the network then you could do a pen test the following year.

                                      Same thing. What do you think an assessment will do that a pentester won't (and vice versa)?

                                      A Pentester is more focused on actually breaking into your network. They will show you the security holes and vulnerabilities they found while exploiting your network, but their focus is exploitation.

                                      An assessment will take everything into account on your network and interview various people about policies and procedures. There more of a focus on finding security vulnerabilities and how to fix them vs breaking in.

                                      So you should only get a pen test when you consider your organization ready for it. Otherwise it can be a waste if there are holes galore in your network.

                                      1 Reply Last reply Reply Quote 1
                                      • C
                                        Carnival Boy
                                        last edited by

                                        Ok, so how does an assessment find out if your applications are vulnerable to SQL injection (for example)?

                                        IRJI 1 Reply Last reply Reply Quote 0
                                        • IRJI
                                          IRJ @Carnival Boy
                                          last edited by

                                          @Carnival-Boy said in Pentest - Who would you recommend?:

                                          Ok, so how does an assessment find out if your applications are vulnerable to SQL injection (for example)?

                                          It's all in the scope of work. You just need to state that you want web apps to be included in the report. Companies ask for this type of stuff quite often. There are plenty of tools that Cyber Security personnel use for this purpose.

                                          The scope of work is the single most important thing you and whatever your company chooses need to agree on.

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            Carnival Boy
                                            last edited by

                                            That's not what I'm asking. I'm asking how does an assessment find out if your applications are vulnerable to SQL injection?

                                            Literally, how, if not by pen testing them?

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post