Penetration Testing Guide for Buyers
Scan vs Assessment vs Pen Test: What to Use and When
Clear deliverables, fixed scope, free retest. Code and cloud reviews.
Introduction
I designed an Augmented Reality (AR) CTF for an event for Leigh Hackspace CIC initially aimed at children, but open on the day to people of all ages. The CTF comprised of a web application as well as a physical component. The code for the web application is located on GitHub at the following URL GitHub Repository. When designing a CTF, several considerations must be made, such as the technical capabilities of the target audience, and the difficulty of which flags (ghosts) can be obtained.
Every day, more companies are joining the sanctions club by restricting access to their services and products to end-users in Iran. These sanctions were supposed to target the government of Iran but day after day it’s turned into a direct weapon against Iranian citizens who, uninvolved in politics, are being punished because of their nationality. In the latest movement, US sanctions hit the Iranian regime’s tech and media industry on January 25th 2020. Fars News Agency’s website, the state-run propaganda machine of the Revolutionary Guard, has been officially prevented from accessing certain media, affecting many.
Something that gets talked about a lot on the internet is password security and password hygiene. Everyone has heard that it’s best practice to use long passwords that are unique and complex, but I want to write a short post about why those things are important, how passwords are stored by websites, and what that means for you. The first thing to mention is USE PASSWORD MANAGERS. It’s the most important thing for keeping your accounts secure! If you don’t know what they are, it’s software that helps you generate unique passwords.
I often feel that blue teaming doesn’t always get the love it deserves, so we decided that this month’s SkillSec would be about Red vs Blue. For those that may not be familiar with these terms, Red is the “offensive” side of security (think “attack simulation”) and blue is about defending i.e. detecting and stopping the attackers. As is often said, blue can be more challenging as you have to defend every weakness whereas with Red, you only have to find one weakness. Both are important to consider.
Security consultants tend to specialize fairly early in their careers, and one of the areas I chose to specialize in, and something that Digital Interruption offers our clients, is mainframe security assessments. For many of us, unless you’re over a certain age, or have a strange fixation on weird machines, you’ll likely have never interacted with a mainframe before. There are a few popular (and contradictory) myths in the infosec community about mainframes:
- They’re legacy
- They’re the same as supercomputers
- Nothing a cluster of cloud computers can’t beat
- Nobody uses them anymore
This blog is an extension of my Arcane Arts of Linux talk at Steelcon 2018, as well as a quick discussion about a post-exploitation tool I’ve been writing and playing with for the last few months, called Orc. Part of the inspiration for this post is that over recent years, there’s been a lot of conversation about red-team techniques for Windows, significant tool development and evolution, and generally quite a lot of progress. Linux, on the other hand, doesn’t receive nearly as much attention.
I’m excited to join the growing Digital Interruption team as Head of Defensive Security! Part of what drew me to DI is the promise of doing security differently – from the transparent, clear pricing model to the focus on continuous security, baking it into the SDLC, supported by policy guidance. My background is very much the attacking side of security – I’ve spoken at multiple conferences about tool development and finding vulnerabilities in obscure systems.