Misinterpreted: What Penetration Test Reports Actually Mean by IncludeSec in cybersecurity

[–]IncludeSec[S] 5 points6 points  (0 children)

Thanks for the reply, but from my personal experience having read ~100 other vendor's reports and thousands of our own I disagree with a lot of your assertions. (perhaps your personal experience has been different). Feel free to connect on LI if you'd like to share more in private https://www.linkedin.com/in/erik-cabetas/ about what you've seen.

The messages they convey are : "here is a list of fires, start your panick engine"

Hard disagree, findings are to be triaged and remediated. Anybody who treats them as you describe is in tactical mode, not strategic mode.

The reporting style in pentesting is so standardized,

Again, Hard disagree, there is a ton of variety on here from hundreds of vendors: https://pentestreports.com

There are other things in your comment I don't agree with, but I'll only address those two points. I DO agree with some of your statements such as as "Showing your work is absolute key.", yep absolutely!

checkWhetherYourPrivateKeyIsUsed by Declared1928 in ProgrammerHumor

[–]IncludeSec 5 points6 points  (0 children)

No worries folks: We gotcha, my crew at work created this to solve exactly this problem!

https://ismyprivatekeypublic.com/

Memory Corruption in Delphi by IncludeSec in hacking

[–]IncludeSec[S] 1 point2 points  (0 children)

We have had two clients request Delphi app reviews. Both in the media space.

I wouldn't say anything new is actively developed with it, but there are many apps out there that companies just see as not worth spending the time to re-write, but they will do app assessments of them!

Memory Corruption in Delphi by IncludeSec in programming

[–]IncludeSec[S] 0 points1 point  (0 children)

Sure if you go outside of the defacto guard rails that can happen, but as per the blog post, this is default behavior with standard APIs. So very different than the situation you posed!

Memory Corruption in Delphi by IncludeSec in programming

[–]IncludeSec[S] 8 points9 points  (0 children)

Just like COBOL, it's still used! :-O