TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Have you performed a penetration test for your company?

4 点作者 lmorandi大约 1 年前
I&#x27;m a penetration tester with more than 5 years of experience working for a well known big4, and now I&#x27;m starting my own company.<p>This being said, I need information about prices, so if you have performed a penetration testing for your company, could you please tell me what what was the duration of the pentest and how much did you pay?<p>Apart from that, since I&#x27;m just starting, I&#x27;m looking for a few clients to build my portfolio, so I will be offering a free web application 1 week penetration test for the first 5 people from HN that contact me.<p>https:&#x2F;&#x2F;www.linkedin.com&#x2F;in&#x2F;lautaro-morandi&#x2F;

2 条评论

ceinewydd大约 1 年前
Pricing tends to be a spectrum. If I’m just getting a report which interprets some commonly-used scanners, that’s cheap(er) — this feels like a “Box Check” test if I gave it a term. When someone’s going beyond scanners and digging into source code to find issues — that’s often more valuable. Bringing specialized knowledge about cryptography to evaluate our implementation? Also more valuable!<p>Beyond pricing have you thought about your differentiation, or what’s special about you? Are you able to do web applications, but i.e. intending to be focusing on industrial control systems, financial systems? Are you going to be comfortable auditing C# or Rust and identifying issues? Do you know a lot about Kubernetes? Are you focusing on cloud environments, if so, are you more specialized on AWS, Azure or GCP?<p>Next thing I think is important to be able to answer: why award the business to you over Deloitte, or over a smaller shop with a good reputation like Cure53, Trail of Bits, TrustedSec, etc? Perhaps you’re a prolific speaker in the security community at Black Hat, Defcon, CCC, or something?<p>If you’re going to be a one-man band, does that rule out engagements large enough to require 5 people for a month? (Sometimes engagements are urgent and multiple people sure helps them go faster).<p>Good luck on the new venture.
评论 #40169303 未加载
评论 #40169157 未加载
b20000大约 1 年前
Penetrating is important.