4 ms·
After their weeklong "penetration test" concluded, I found some serious XSS (public user->admin, which could easily turn into system takeover) with about 5 minu
by strayptr 11y ago
After their weeklong "penetration test" concluded, I found some serious XSS (public user->admin, which could easily turn into system takeover) with about 5 minutes of looking. Are most audits this useless?
Hiya! I started at Matasano/NCC back in February. Part of the reason I joined was to find out whether or not everything tptacek has been saying for years is true. Turns out it's pretty much all true. Some of that is awesome, like the hiring process. Some of that is scary, like the fact that someone of moderate skill level can usually break into most production apps.
My experience is limited. That said, put me on an audit and the first thing I'll check for is XSS and SQLi. The second thing I'll check for is authz: log into an admin account, note a URL to perform an admin action, log in as a normal user, try to access that URL. Third thing I'll check for is if there are any upload forms, because that's a common way to get RCE: upload a file and try to trick the app into executing it. Etc. Stuff that matters.
It's a point of pride to ensure that our assigned app has been pentested thoroughly by the conclusion of an audit. A thorough pentest doesn't necessarily mean finding every possible vulnerability, because time is often limited, but it does mean finding the serious ones.
If we include any findings in the final report which could be called "trivial" (there are occasionally some), they're marked as informational findings, i.e. their severity level is less than low. The reason we include them is because even though the finding doesn't necessarily pose any security risk, a client will often get another pentest from another security firm and diff the results. If the other firm points out something we thought was too trivial to include, the client will rightfully ask why we didn't find it. (We try to be pretty clear in the report about each finding, though, so you're not going to come away with the impression that we're saying you need to address something trivial.)
I don't know enough about your experience with that security firm you worked with to comment directly, but communication is one of the most important aspects of the job. If we find some flaws but don't communicate well to the client, then nobody was served by the audit. So if you're feeling like the whole process was a waste of time, you might want to shop around. There are several good security firms, not just Matasano/NCC, so you may want to give it another shot.
For what it's worth, the fact that you had a bad experience with one of the firms is actually painful to me. It's only recently that people started to care about security in a significant way, and it's a tenuous position. The more people who get a "security audit" and end up feeling like it was a waste of time, the more likely we are to end up back in a situation where people know there are probably serious security problems but feel like there's nothing they can do to find or fix them. There is: Give us a test environment and two weeks. We'll find what matters, and we'll give you a report explaining each issue and how to fix them.
- smu 11y agoThank you for your comment! I want to add to it as a former pentester: it's absolutely painful to read about these nitpicky "the world is going to burn if you don't modify trivial security setting X that will destroy user experience". Not because these shouldn't be included in the report, but because the focus is wrong. As strayptr, I would also include the trivial issues as "informationals" in the report as you do want your clients to know about these for a number of reasons. However, most of my time would go to hunting for severe issues, where I defined severe on some mental ranking based on "difficulty to exploit", potential impact,... In addition, these issues were also where most of my attention went to afterwards, because you need to explain and educate development, testing and business on the issues, why you think they are important and how to best/quickest fix them. In my opinion, building up relationships and having empathy for your client is very important. I would always try to have a chat with development/test/business to get a feel of where their heads were at. That would help me both while testing (what is important to them? how did they develop it? what is their maturity?) and while reporting issues (they would actually believe me, I could help them rank the issues and they would allow me to brainstorm how to best mitigate the issues for their environment).