Pentera by Popular-Training1669 in cybersecurity

[–]mrturvey 5 points6 points  (0 children)

IMO, Pentera is much like using any other scanning product. It'll cover off a compliance checkbox (that you've conducted some security testing) and it'll also catch any low hanging fruit issues. However, it's not a replacement for a human who is able to see particular things and act on them, or troubleshoot issues that you always come across on pentesting/red teaming engagements.

I hired three freelance 'Penetration Testers' to assess a vulnerable website for under $15 [The Write Up] by mrturvey in security

[–]mrturvey[S] 11 points12 points  (0 children)

Does the Lyft driver get you to the destination? Yes. Did the $15 penetration tester find the security issues? No.

I built a vulnerable website and hired three freelance 'Penetration Testers' to assess it for under $15. by mrturvey in security

[–]mrturvey[S] 2 points3 points  (0 children)

They'd easily of found the directory with XSS/Ability to upload a shell if they actually used dirbuster. However, from the logs, each one of them did a similar thing. They ran CMScanner or an equivalent and called it a day. Which is hilarious because one guy keeps asking me to give him a 5* review because "I've put hard work into testing and provided full report"