Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 31 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Career Centralarrow What should one pay for a pen test?
Ethical Hacker Community Forums
December 02, 2008, 04:41:23 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: 1 [2]   Go Down
  Print  
Author Topic: What should one pay for a pen test?  (Read 6605 times)
0 Members and 1 Guest are viewing this topic.
dannioni
Newbie
*
Offline Offline

Posts: 44


View Profile
« Reply #15 on: February 28, 2008, 02:06:44 AM »

Well, thats another advatage for me, I'm *maybe* the only one in a 100km radius that does these things. I was thinking about roughly 50 dollars, so i've got it confirmed, and i'll see what the feedbak is from the customers. And thank you all replies, on topic and otherwise Cheesy
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 348


View Profile
« Reply #16 on: February 28, 2008, 02:04:28 PM »

For general PC work, charging by the hour is usually fine with some kind of cap for the customer. Obviously they are not going to pay you 2 full days of labor to install a simple hard drive. 

For security work, you figure what your time is worth and how long you think it will take to do a decent audit. It takes some experience to know how much time you need to spend.  Take the amount of hours you feel comfortable with and times that by what the market will handle. Then bid that as a flat rate. In my experience and I sure other's experiences vary, customers want a flat bid. If you just say I charge X amount per hour, they have no idea where you are going to end up and how open ended your charge is going to be. Large firms can bid 10,000 - 50,000 and higher for big clients. But they will often send a group of people as a tiger team.  Once in a while we hear stories of a large company charging through the roof only to send in a person that runs a Nessus scan, then prints out a pretty report that’s fluffed up to look large and that’s it. What's really scary is when you find out that is not just a "story" but what really happened!
« Last Edit: February 28, 2008, 02:11:12 PM by Kev » Logged
dannioni
Newbie
*
Offline Offline

Posts: 44


View Profile
« Reply #17 on: February 29, 2008, 06:33:32 AM »

I just don't print the nessus scan, I also tell them they're in  deep shit and should probably hire someone to fix it *pointing at self*, should I charge extra for that?
Logged
Mr. Roboto
Jr. Member
**
Offline Offline

Posts: 67


Himitsu wo shiritai


View Profile
« Reply #18 on: February 29, 2008, 07:31:26 AM »

Kev's comments make a lot of sense.  Sounds right on the money. 

I assume a company will have no idea how many hours will be involved in a pen test, too many variables.  I'm positive they'll know how much they are willing to pay for it though!
Logged

A+, Security+, HDI Support Center Analyst, MCTS: Vista
pseud0
Full Member
***
Offline Offline

Posts: 143



View Profile
« Reply #19 on: February 29, 2008, 09:12:12 AM »

Sadly, I see situations similar to what Kev mentioned all the time.  One of our new clients was a victim of this for about 3 years in a row. Gave the work to a VERY large company, and at the end of the year the results looked oddly like nessus scans copy and pasted into a different format.  Last year they tore up the contract an moved over to us.  Even within the same company it can really vary by office.  We just had an office in another midwest state piss off one of their large customers because they did something along these lines.  They had just started a new project for someone else and it was tying up all of their best testers.  The management thought they could get away with sending "the B team" over to the old client, kicking off some scans, and then tap dance through the rest.  Our relationship with the customer now resembles a smoking hole in the ground.  The managers still planned on sending over the "real" testers before the end of the project to do some good work, but they didn't get the chance as it blew up in their faces before then.  Anyway, morale of the story is that your can make your career and reputation by coming in after one of these situations and helping the customer get real value.  You get to play the white night.
Logged

CISSP, CISM
sgt_mjc
Full Member
***
Offline Offline

Posts: 158


View Profile
« Reply #20 on: February 29, 2008, 09:20:32 AM »

The scary thing with Nessus is that it can shut down a network. What are those companies thinking?
Logged

Mike Conway
CompTia Security +
C|EH
pseud0
Full Member
***
Offline Offline

Posts: 143



View Profile
« Reply #21 on: February 29, 2008, 11:14:42 AM »

As long as Nessus is on your list of approved tools and they signed the letter of authorization you are fairly safe.  We always give an overview of how we configure each of our tools and the possible impact in an effort to educate the customer before they agree to the testing, but you can't predict every possible risk.  For example, I was doing pen testing on a state government client early last year, and about 2 in the morning the target I was hitting became unresponsive.  I called my emergency point of contact who called the system owner.  The next morning we were getting our assess chewed out for being "reckless", and the system owner said we had done permanent damage to the box.  We found out later that day that the fans in the server had stopped working about a week before, and we just happened to be touching it when if finally melted down.  The system owner was trying to cover his butt by blaming it on us.  We didn't get an apology, but they also didn't question our testing methods anymore.
Logged

CISSP, CISM
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #22 on: February 29, 2008, 05:26:10 PM »

yes nessus can crash boxes but those plugins are disabled by default. it is also possible to tweak it and turn stuff on and off by type of check.  All the comes from experience and not covered in your CEH exam :-P  Breaking stuff is also possible during scans, VA's, and pentests.  The customer should understand that before you start and any mission critical systems should be given to you for proper care.

psedu0 is right though, if there is an act of god on that network pray that it doesnt happen while your activities are going on because you will automatically be at fault; someone else scanning from outside, it was you from the hotel...crap like that...just need to make sure you know whats going on with your activities and you are on your toes.

Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.038 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.