Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 34 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Resources
Career Central
What should one pay for a pen test?
EH-Net
May 23, 2013, 11:21:51 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
What should one pay for a pen test?
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: What should one pay for a pen test? (Read 16707 times)
0 Members and 1 Guest are viewing this topic.
dannioni
Newbie
Offline
Posts: 44
Re: What should one pay for a pen test?
«
Reply #15 on:
February 28, 2008, 02:06:44 AM »
Well, thats another advatage for me, I'm *maybe* the only one in a 100km radius that does these things. I was thinking about roughly 50 dollars, so i've got it confirmed, and i'll see what the feedbak is from the customers. And thank you all replies, on topic and otherwise
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: What should one pay for a pen test?
«
Reply #16 on:
February 28, 2008, 02:04:28 PM »
For general PC work, charging by the hour is usually fine with some kind of cap for the customer. Obviously they are not going to pay you 2 full days of labor to install a simple hard drive.
For security work, you figure what your time is worth and how long you think it will take to do a decent audit. It takes some experience to know how much time you need to spend. Take the amount of hours you feel comfortable with and times that by what the market will handle. Then bid that as a flat rate. In my experience and I sure other's experiences vary, customers want a flat bid. If you just say I charge X amount per hour, they have no idea where you are going to end up and how open ended your charge is going to be. Large firms can bid 10,000 - 50,000 and higher for big clients. But they will often send a group of people as a tiger team. Once in a while we hear stories of a large company charging through the roof only to send in a person that runs a Nessus scan, then prints out a pretty report that’s fluffed up to look large and that’s it. What's really scary is when you find out that is not just a "story" but what really happened!
«
Last Edit: February 28, 2008, 02:11:12 PM by Kev
»
Logged
dannioni
Newbie
Offline
Posts: 44
Re: What should one pay for a pen test?
«
Reply #17 on:
February 29, 2008, 06:33:32 AM »
I just don't print the nessus scan, I also tell them they're in deep shit and should probably hire someone to fix it *pointing at self*, should I charge extra for that?
Logged
Mr. Roboto
Jr. Member
Offline
Posts: 67
Himitsu wo shiritai
Re: What should one pay for a pen test?
«
Reply #18 on:
February 29, 2008, 07:31:26 AM »
Kev's comments make a lot of sense. Sounds right on the money.
I assume a company will have no idea how many hours will be involved in a pen test, too many variables. I'm positive they'll know how much they are willing to pay for it though!
Logged
A+, Security+, HDI Support Center Analyst, MCTS: Vista
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: What should one pay for a pen test?
«
Reply #19 on:
February 29, 2008, 09:12:12 AM »
Sadly, I see situations similar to what Kev mentioned all the time. One of our new clients was a victim of this for about 3 years in a row. Gave the work to a VERY large company, and at the end of the year the results looked oddly like nessus scans copy and pasted into a different format. Last year they tore up the contract an moved over to us. Even within the same company it can really vary by office. We just had an office in another midwest state piss off one of their large customers because they did something along these lines. They had just started a new project for someone else and it was tying up all of their best testers. The management thought they could get away with sending "the B team" over to the old client, kicking off some scans, and then tap dance through the rest. Our relationship with the customer now resembles a smoking hole in the ground. The managers still planned on sending over the "real" testers before the end of the project to do some good work, but they didn't get the chance as it blew up in their faces before then. Anyway, morale of the story is that your can make your career and reputation by coming in after one of these situations and helping the customer get real value. You get to play the white night.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: What should one pay for a pen test?
«
Reply #20 on:
February 29, 2008, 09:20:32 AM »
The scary thing with Nessus is that it can shut down a network. What are those companies thinking?
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: What should one pay for a pen test?
«
Reply #21 on:
February 29, 2008, 11:14:42 AM »
As long as Nessus is on your list of approved tools and they signed the letter of authorization you are fairly safe. We always give an overview of how we configure each of our tools and the possible impact in an effort to educate the customer before they agree to the testing, but you can't predict every possible risk. For example, I was doing pen testing on a state government client early last year, and about 2 in the morning the target I was hitting became unresponsive. I called my emergency point of contact who called the system owner. The next morning we were getting our assess chewed out for being "reckless", and the system owner said we had done permanent damage to the box. We found out later that day that the fans in the server had stopped working about a week before, and we just happened to be touching it when if finally melted down. The system owner was trying to cover his butt by blaming it on us. We didn't get an apology, but they also didn't question our testing methods anymore.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
LSOChris
Guest
Re: What should one pay for a pen test?
«
Reply #22 on:
February 29, 2008, 05:26:10 PM »
yes nessus can crash boxes but those plugins are disabled by default. it is also possible to tweak it and turn stuff on and off by type of check. All the comes from experience and not covered in your CEH exam :-P Breaking stuff is also possible during scans, VA's, and pentests. The customer should understand that before you start and any mission critical systems should be given to you for proper care.
psedu0 is right though, if there is an act of god on that network pray that it doesnt happen while your activities are going on because you will automatically be at fault; someone else scanning from outside, it was you from the hotel...crap like that...just need to make sure you know whats going on with your activities and you are on your toes.
Logged
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.