Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 54 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Programming
Where to find ethical hacker to review code/ give instructions on fix.
EH-Net
May 24, 2013, 10:01:59 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Programming
(Moderator:
don
) >
Where to find ethical hacker to review code/ give instructions on fix.
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Where to find ethical hacker to review code/ give instructions on fix. (Read 4050 times)
0 Members and 1 Guest are viewing this topic.
newbie101
Newbie
Offline
Posts: 3
Where to find ethical hacker to review code/ give instructions on fix.
«
on:
February 27, 2012, 04:21:52 PM »
My situation is this. I outsourced a fairly large project. We have just finished up and im sure there are security holes all over the place. I actually had someone run some software and found minor mysql injections issues.
My question is this. From a subjective view (im not technical) what would be the best/smartest way to have someone who knows hacking review my code and give me instructions on fixes.
Currently i have
-ran software (that guy was good but got busy and bailed on me)
-posted some jobs on elance (about 2-3 highly reviewed people bid but still not sure if its the smartest route.
-finally there is a good college nearby with a really good computer science department. Tomorrow i plan on driving there and trying to get an undergrad to start reviewing code.
I would like to hear some feedback, from a non technical standpoint, knowing what you all know, what is the best strategy to securing my website up. Over 500 hour project so far, so pretty big. I noticed when it was too late they are using some GET and POST variables where most likely they shouldn't be. So again, id appreciate the feedback.
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #1 on:
February 27, 2012, 09:47:56 PM »
My company does this if you want a professional organization to have a look. PM if you want more information.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #2 on:
February 29, 2012, 03:48:23 PM »
Talking about proprietary vectors, there's also Hatforce
(There's both public and private / trusted tests, contact them for more info.)
Anyway, I do suggest that you either go through the code, or get someone else to do it. Don't make a program do it for you naturally, as it may as you say, contain several vulnerabilities.
This depends on the developer, if he or she is skilled at writing secure code to protect against (at least) the most common attack vectors nowadays.
It sounds like a good idea to e.g., give an undergrad or someone else a look at your code, but keep in mind, that if this person whether he or she says they know infosec or not, doesn't make it hackproof.
For the most optimal security, you need at least one (skilled) ethical hacker (NOT certified ethical hacker), penetration tester, code reviewer, etc., to test your application. In other words, you need someone who "loves" information security (infosec), who knows their field, and capable of mitigating any risks in the app.
The best way, is to either:
A) Make your app open source so anyone can read the source and hope some hackers review it and make advisories
B) Hire an external company
C) Use it on a website and wait until someone might hack it. (Some companies seems to go with this option, even though I don't recommend it
)
Logged
I'm an InterN0T'er
newbie101
Newbie
Offline
Posts: 3
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #3 on:
March 01, 2012, 07:46:18 AM »
Quote
For the most optimal security, you need at least one (skilled) ethical hacker (NOT certified ethical hacker), penetration tester, code reviewer, etc., to test your application. In other words, you need someone who "loves" information security (infosec), who knows their field, and capable of mitigating any risks in the app.
i agree with this, but i can not find a local guy or anywhere for that matter in which i trust. Problem is its really holding back my launch, and i must get some people there first (like groupon getting businesses to the website first). So i am just trying to figure out the fastest way of doing this and ofcoarse without paying some external 10k to try to hack the site.
You say not "NOT certified ethical hacker" can you tell me why, im guessing they are not good enough p.s. im in NY about 25 mins from manhattan, where would you guys go or how would you pick up an ethical hacker if you knew nothing about it with. Again please its really holding my launch up.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1060
aka dynamik
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #4 on:
March 01, 2012, 08:19:35 AM »
Quote from: newbie101 on March 01, 2012, 07:46:18 AM
i agree with this, but i can not find a local guy or anywhere for that matter in which i trust. Problem is its really holding back my launch, and i must get some people there first (like groupon getting businesses to the website first). So i am just trying to figure out the fastest way of doing this and ofcoarse without paying some external 10k to try to hack the site.
The unfortunate reality of this situation is that securing the application at this point is going to be more time-consuming and expensive since security was an afterthought. I'm not trying to rake you over the coals, but you would have been in a much better position had security been a consideration (and priority) from the start.
If you're serious about this, you should probably avoid students and people looking for work via reverse-auctions online. This type of service requires years of experience and a high level of expertise.
This has now become a business decision where you must weigh the costs of delaying your launch and paying a high cost for professional services to going live immediately and risking an incident that may cause a loss of reputation, or worse scenarios.
You also have to consider the type of data you'll be protecting. Any type of incident is obviously undesirable, but there's a significant difference in impact when you compare an image hosting service and an online banking service. The amount of time and money you invest into security should be proportional to criticality of the data you're trying to protect. You might want to try conducting an informal risk assessment in order to estimate some numbers.
Quote from: newbie101 on March 01, 2012, 07:46:18 AM
You say not "NOT certified ethical hacker" can you tell me why, im guessing they are not good enough
This is kind of an inside joke. It's a broad certification, and despite it's name, it's really not an accurate indicator of someone's actual skills. That's not to imply that all CEHs are unskilled, just that you shouldn't take it at face value and should also considered other certs, education, work experience, etc.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
newbie101
Newbie
Offline
Posts: 3
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #5 on:
March 01, 2012, 09:00:58 AM »
Yes i have been searching around i see that being certified is like going to college, many graduates that are smart, but many that know less than a hobo with some experience.
Something actually just came up as i sat and stressed, i realized my cousins best friend does security at a big bank (either manager or physically does the work), they have been best friend for 20 years, he makes real deal money so has no need to steal from little me etc, and he can be trusted. I will call him later and try to get him onboard and hopefully it will be cost efficient. My goal is not even making the security extremely tight right now but i think it would be ridiculous and naive of launching without having a "expert" look at it and either say... hey your screwed, but good luck, or its not that bad just do X.Y, and Z.
Ive built a pretty complex and dynamic site in PHP so im sure there are issues. I had someone review it and said its not bad really at all... he got too busy flying around consulting, i just couldent take the down time... but i think this otherguy will really work out because he will care as if its his own not someone bidding on elance.
I also know someone working at cisco systems, hes a big guy there, he has to know someone who can do this who is good and i can trust, ill reach out to him as well. Googling my way out of this problem obviously isnt happening, time to get away from the computer to solve a computer problem if that makes any sense? Time to use that thing, a pone or phone i think it called.
Logged
sternone
Full Member
Offline
Posts: 129
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #6 on:
August 08, 2012, 02:23:07 PM »
500 hours total of coding is a project is nothing. That's not a big project.
Reading your post makes me feel that you want the best of the world without paying anything.
"If you give peanuts you get monkeys"
Good luck.
Logged
Try harder....hmpf!!
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Where to find ethical hacker to review code/ give instructions on fix.
«
Reply #7 on:
August 09, 2012, 03:30:24 AM »
Yes that is total ture I would perfer to pay as least I know there is a good chance they do a good job
Logged
OSWP | Hackingdojo Nidan | eCPPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.