Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 20 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Pentest: Working in team or alone?
EH-Net
May 19, 2013, 01:35:47 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Pentest: Working in team or alone?
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Pentest: Working in team or alone? (Read 7159 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Pentest: Working in team or alone?
«
on:
September 21, 2010, 09:32:21 AM »
I was wondering...
To the professional pentesters, do you work alone or in team?
On one hand, working in team is probably better. It's impossible to "know it all" and you can have experts on different topics. You can also discuss ideas and try to help each other. You can also finish the pentest faster.
But my reality is that companies that I work for are cheap, especially these days. They want a cheap pentest completed as fast as possible. The last two contracts I have got wouldn't pay the salary of two pentesters.
Also, I didn't hear much of "teamwork" on this forum. So hence my question, do you work in team and why?
I am so curious...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
mambru
Jr. Member
Offline
Posts: 98
Re: Pentest: Working in team or alone?
«
Reply #1 on:
September 21, 2010, 09:45:40 AM »
We have a Tiger Team with 8 members, and depending on the dimension of the engagement and time we have to finish, we work either alone or in a small group (not more than 3).
I think working in team yields very good results, since as you say, a single person can't know everything.
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Pentest: Working in team or alone?
«
Reply #2 on:
September 21, 2010, 11:08:02 AM »
I worked alone (for free / fun) at a company once, but later on I had to train another employee the basics to get started so I worked in a team but it wasn't really a team when the other employee was at that time just a trainee
But it was nice to have company instead of stressing about everything myself
(I was under huge time pressure every time, like.. You got 2 hours to prove there's something big time wrong with their network
)
However, back on topic. I believe a team of experienced Penetration Testers is definitely a big plus, in fact I believe they are probably able to achieve more if one is e.g. expert in Web App Sec, another in Software Exploitation, a third in Reverse Engineering, a fourth in Social Engineering etc.
«
Last Edit: September 21, 2010, 11:09:54 AM by MaXe
»
Logged
I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Pentest: Working in team or alone?
«
Reply #3 on:
September 21, 2010, 06:02:40 PM »
I totally agree. I'm almost always alone, and I hate it. I'd much rather work with someone else. There's just a synergy that consistently produces better results; it goes beyond simply having different areas of expertise. Having someone else to brainstorm with really helps generate ideas.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Ketchup
Hero Member
Offline
Posts: 1021
Re: Pentest: Working in team or alone?
«
Reply #4 on:
September 21, 2010, 06:45:39 PM »
I definitely wish that I was part of a team sometimes. Bouncing ideas off another person can really save time and headaches. Unfortunately, that rarely happens for me. This is why this place is so valuable to me. Even if it is after the fact, I can still learn something new.
Logged
~~~~~~~~~~~~~~
Ketchup
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Pentest: Working in team or alone?
«
Reply #5 on:
September 21, 2010, 08:11:43 PM »
Quote
I'm almost always alone, and I hate it.
Quote
I definitely wish that I was part of a team sometimes. Bouncing ideas off another person can really save time and headaches. Unfortunately, that rarely happens for me.
It is the same with me. I am always alone and, even worst, I am still just starting in this field!!! I really work hard to check every little things, trying not to forget anything. But I have to figure out methodologies and tools all by myself. I would really appreciate working with a more experience pentester. I feel I would learn 6000 times faster...
But the worst thing is, did I miss anything?!? At least, everytime, I feel I gave everything I could. Ahhh, it's so hard to get experience!!!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
impelse
Hero Member
Offline
Posts: 563
Re: Pentest: Working in team or alone?
«
Reply #6 on:
September 21, 2010, 10:36:06 PM »
I do not know guys, I am still learning but why you do not partner with somebody that will help you remotely sometimes in some specific areas. It is not easy is like a marriage but you can try.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Pentest: Working in team or alone?
«
Reply #7 on:
September 22, 2010, 06:50:21 AM »
Quote from: impelse on September 21, 2010, 10:36:06 PM
I do not know guys, I am still learning but why you do not partner with somebody that will help you remotely sometimes in some specific areas. It is not easy is like a marriage but you can try.
I'll occasionally text or email other members of my team who are back at the office or at some other location if I think they can provide some insight into what I'm dealing with. That's not the same has having multiple people dedicated to the same project/engagement though.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
H0nd0CSI
Newbie
Offline
Posts: 17
H0nd0
Re: Pentest: Working in team or alone?
«
Reply #8 on:
September 23, 2010, 09:50:25 AM »
It’s been my dilemma for a long long time
IN a perfect world ye right
I typically only take on Pen Tests that are larger, so I can incorporate a small team to get the best results. I am no expert in every area like Cisco, DB, Coding etc, so I plan the assessment based on doing what I can knowingly do very well and then bring in specific experts in the other areas where my skills are lacking expert levels. Its tough when companies dictate what resources you have available. So we just learn to be creative and think outside the box
Logged
"If the only tool you have is a hammer, you tend to see every problem as a nail"
Abraham Maslow
T_Bone
Full Member
Offline
Posts: 199
Re: Pentest: Working in team or alone?
«
Reply #9 on:
September 27, 2010, 02:06:47 AM »
This is a topic I am also very interested in. I currently work alone and I am a junior level Pen tester! It frustrates me a lot because I want to learn from others and understand where I may miss things and maybe even show my seniors a thing or two. I asked a similar question in the thread below. I believe it does depend on the company though as I have a few friends here in the UK whom have informed me that there must be at least 2 people working on one assignment.
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,6069.0/
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Pentest: Working in team or alone?
«
Reply #10 on:
September 27, 2010, 08:27:23 AM »
Quote
I currently work alone and I am a junior level Pen tester! It frustrates me a lot because I want to learn from others and understand where I may miss things
Very good comment, which bring this question:
I am too, a junior pentester. I work in a small city where it is very difficult to find other pentesters. Can I work as a pentester, without having a more senior guy watching over my shoulder?
I try very hard to do the best job possible, but knowledge is power. I can certainly find the "low hanging fruits" and even the medium ones, but where I can maybe find one or two high ones, I am not sure at all if I had miss a few...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
T_Bone
Full Member
Offline
Posts: 199
Re: Pentest: Working in team or alone?
«
Reply #11 on:
September 27, 2010, 04:07:12 PM »
@H1tM0nk3y - I hear ya!
I too perform tests and 9 out of 10 times I will find XSS, XSRF, Logic Flaws, Access control issues, but have certainly realised that blind SQLi is not my strong point and am almost sure I have missed it on some tests... Format string vulnerabilities are not soo easy for me either.... I have been doing this for almost 6 months so am new to it but really really have a hunger to know that I have covered all areas.... Apparently my work is being checked by my more senior team members but what does "checked" mean? If they are not performing a thorough test, surely they will only pick up the long hanging fruit also??
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Pentest: Working in team or alone?
«
Reply #12 on:
September 27, 2010, 06:14:46 PM »
T_Bone, we are in the same boat...
And I see another one coming: being asked to be an incident handler at the last minute... Where I work, no one can do this job. Yes, I see this coming big time...
In this case, I will only accept to do it while a more competent company takes over (like, within an hour or so!). I could definitively stop an attack, but I will certainly screw up forensic evidences and so on.
Like being junior in the pentest world (but at least not in IT!), every security problems come to me since I am the only one where I work who "can" handle these things. I guess I have to see it as if I don't do it, no one will.
But that being said, I am not a complete ignorant either!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
facsimil3
Newbie
Offline
Posts: 6
Re: Pentest: Working in team or alone?
«
Reply #13 on:
October 20, 2010, 11:50:41 AM »
I'm my personal opinion, its always better to have a team, since working with other guys can be less stressful and besides can help you find out the things that you are missing.
you cant be a guru in everything.
besides you have somebody to talk too and discuss other ways of performing the tests.
Logged
T_Bone
Full Member
Offline
Posts: 199
Re: Pentest: Working in team or alone?
«
Reply #14 on:
October 21, 2010, 06:02:33 AM »
@ facsimil3
This is exactly how I see it!
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(6) by
Grendel
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.