Author Topic: How deep do you go ;) ?  (Read 795 times)

0 Members and 1 Guest are viewing this topic.

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
How deep do you go ;) ?
« on: October 23, 2014, 10:17:42 am »
Okay so when performing a penetration test, you have done all your research, you have spent hours on the job to get your list of hosts and there open ports,

after performing your scan you manage to find 'x' amount of vulnerabilities and you also know how to exploit them,

E.g with a remote connection, command terminal execution or a buffer overflow.

How far do you go?

- Do you leave it as that, write/export your report and send it off.
- You exploit the system and then write your report, showing that you did the exploit (risking damage?)
- You perform the exploit and then have a look around? You might find something interesting...

What are your thoughts?
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: How deep do you go ;) ?
« Reply #1 on: October 23, 2014, 02:52:18 pm »
That depends on the job. If you are allowed to exploit you exploit, if you can look at their data you look at their data.
~Factionwars

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How deep do you go ;) ?
« Reply #2 on: October 23, 2014, 03:21:06 pm »
I go by what they requested, what would you do if you were just trawling?
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: How deep do you go ;) ?
« Reply #3 on: October 23, 2014, 04:48:55 pm »
Just trawling? I don't pentest random sites, get a contract or stay the heck away; otherwise you'll most likely end up in troubles.
"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How deep do you go ;) ?
« Reply #4 on: October 23, 2014, 04:56:38 pm »
My job is a Ethical Hacker/Administrator , I was just wandering if people Trawl?

I mean I do sometimes but usually only sites that are related to my work...

~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline Phage

  • VIP
  • Overlord
  • *
  • Posts: 1280
  • Cookies: 120
    • View Profile
Re: How deep do you go ;) ?
« Reply #5 on: October 23, 2014, 05:12:31 pm »
My job is a Ethical Hacker/Administrator , I was just wandering if people Trawl?

I mean I do sometimes but usually only sites that are related to my work...

No chances taken from my side.

If they want a pentest, they can sign me a contract.
« Last Edit: October 23, 2014, 05:12:53 pm by Phage »
"Ruby devs do, in fact, get all the girls. No girl wants a python, but EVERY girl wants rubies" - connection

"It always takes longer than you expect, even when you take into account Hofstadter’s Law."

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How deep do you go ;) ?
« Reply #6 on: October 23, 2014, 05:43:48 pm »
No chances taken from my side.

If they want a pentest, they can sign me a contract.

Fair play, that's how I usually do things.
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: How deep do you go ;) ?
« Reply #7 on: October 23, 2014, 06:26:04 pm »
~Factionwars

Offline Pak_Track

  • Royal Highness
  • ****
  • Posts: 762
  • Cookies: 69
  • Paratrooper
    • View Profile
    • My Home
Re: How deep do you go ;) ?
« Reply #8 on: October 23, 2014, 07:03:22 pm »
^yep, that's what crossed my mind when I saw this thread :P

'Life is but a series of conflicts between the easy way and the right way.'
The more you know, the more you'll realize you know nothing. -Snayler
The problem with being a smart motherfucker is that sometimes the stupid motherfuckers think you're a crazy motherfucker.
dont u hate it when you offer help and the other person says yes -Pakalu Papito

Offline Nortcele

  • Knight
  • **
  • Posts: 211
  • Cookies: -42
  • █+█=██
    • View Profile
Re: How deep do you go ;) ?
« Reply #9 on: October 23, 2014, 07:46:47 pm »
Thats what I was intending people to think, hence the winky face ;)
~JaySec
~LulzBlog

TAKE A COOKIE!




0100000101010011010000110100100101001001