Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

1/17/2020
10:45 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

7 Ways to Get the Most Out of a Penetration Test

You'll get the best results when you're clear on what you want to accomplish from a pen test.
Previous
1 of 8
Next

Image Source: Adobe Stock: Leowolfert

Image Source: Adobe Stock: Leowolfert

Here's what you don't want from a pen test: A 600-page report packed with detail that overwhelms everyone in your organization.

Andrew Hay, chief operating officer at Lares, a security consultancy, says he's seen too many times where pen testers overload their customers with so much information that they don't wind up doing anything with the results.

"Too often people receive that 600-page report and it looks like a vulnerability scan; they don't know what to do with it," says Quentin Rhoads, director of professional services at Critical Start.

Hay and Rhoads say the best pen tests are targeted. So start with a scoping interview where you identify what you want to get out of the pen test. If you don't get pen tests every year, it's unrealistic to think you'll be able to fix everything in your network from just one test.

Here are seven tips that Hay, Rhoads, and Rapid7’s Tod Beardsley offer up to companies looking get their money's worth out of a penetration test.

 

 

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Two Vulnerabilities Found in Microsoft Azure Infrastructure
Kelly Sheridan, Staff Editor, Dark Reading,  1/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Up you go.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20104
PUBLISHED: 2020-02-06
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
CVE-2019-20106
PUBLISHED: 2020-02-06
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
CVE-2019-20400
PUBLISHED: 2020-02-06
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
CVE-2019-20401
PUBLISHED: 2020-02-06
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
CVE-2019-20402
PUBLISHED: 2020-02-06
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.