Penetration Testing Guide for Buyers
Scan vs Assessment vs Pen Test
What to use and when. Clear deliverables, fixed scope, free retest. Code and cloud reviews.
Introduction
I designed an Augmented Reality (AR) CTF for an event for Leigh Hackspace CIC initially aimed at children, but open on the day to people of all ages. The CTF comprised of a web application as well as a physical component. The code for the web application is located on GitHub at the following URL https://github.com/leigh-hackspace/spooky_hunt. When designing a CTF, several considerations must be made, such as technical capabilities of the target audience, and the difficulty of which flags (ghosts) can be obtained.
REX – A Vulnerability Scanner
REX is a vulnerability scanner, specifically designed for developers and software testers to help them test the security of Android applications. With REX, you can scan your Android apps as they’re being developed to detect security weaknesses early and often. This is a different approach to traditional penetration testing.
COVID-19 Contact Tracing Application
Since the government announced earlier this week that the COVID-19 Contact Tracing application is to be trialled in the Isle of Wight, there has been a lot of mixed messages and FUD (Fear Uncertainty and Doubt) on both mainstream and social media. While awaiting the app's release, we can review the white paper released by NCSC to understand how the application should work and what kind of privacy and security concerns may exist.
COVID-19 Specific Phishing Campaigns
How attackers are using social media to create COVID-19 specific phishing campaigns. The coronavirus has affected the lives of millions of people and businesses around the globe. Changes in behaviors resulting from the changes we have had to make to live and operate have opened up new attack vectors for attackers. By raising awareness, we can find the right balance of safety and usability.
Sanctions on Iranian Citizens
Every day, more companies are joining the sanctions club by restricting access to their services and products to end-users in Iran. These sanctions were supposed to target the government of Iran but day after day, they have turned into a direct weapon against Iranian citizens.
Password Security and Hygiene
Something that gets talked about a lot on the internet is password security and password hygiene. The best practice is to use long passwords that are unique and complex. The most important thing for keeping your accounts secure is using password managers. If you don’t know what they are, they are software that helps you generate and store complex passwords.
Red vs Blue Teaming
Blue teaming doesn’t always get the love it deserves, so we decided that this months SkillSec would be about Red vs Blue. Red is the offensive side of security (think “attack simulation”) and blue is about defending (i.e. detecting and stopping the attackers). Both are important to consider.
Mainframe Security Assessments
Security consultants tend to specialize fairly early in their careers, and one of the areas I chose to specialize in is mainframe security assessments. There are popular myths in the infosec community about mainframes that need debunking.