I'm don't get paid to do this sort of thing very often, but when I have been paid, the client has always asked for noisy generic scans that can be integrated as part of a periodic review process (for internal or external parties). Explaining that the bad guys won't be so nice as to light up your IDS with an internal portscan or try to brute force some random database was met with complete indifference.
I guess as someone who would be responsible for their network's general well-being, I'd probably rather have some checked boxes saying nothing on my internal network was listening with trivially exploitable (i.e. non-patched or badly configured) services and my passwords are at least a certain complexity and not variations of the 1000 most common as of $SOMEDATE.
That said, it should be pretty easy to setup the usual suspects for scan tools to be performed in a scoped manner to satisfy the need for checked boxes after an operator spends some time getting up close and personal with the target system. Those type of attacks are going to reveal more information about user training (looking at Joe User with important\ passwords.docx in My\ Documents) than simple network scans are likely to.
I wonder what the qualifications are these days for a pen tester at a commerical company...
Most people are looking for someone to perform a cover-your-arse paperwork exercise. By paying someone to port-scan their network, they can say "we receive regular security audits".
The fact that they haven't done a proper penetration test is immaterial.
Comments
I'm don't get paid to do this sort of thing very often, but when I have been paid, the client has always asked for noisy generic scans that can be integrated as part of a periodic review process (for internal or external parties). Explaining that the bad guys won't be so nice as to light up your IDS with an internal portscan or try to brute force some random database was met with complete indifference.
I guess as someone who would be responsible for their network's general well-being, I'd probably rather have some checked boxes saying nothing on my internal network was listening with trivially exploitable (i.e. non-patched or badly configured) services and my passwords are at least a certain complexity and not variations of the 1000 most common as of $SOMEDATE.
That said, it should be pretty easy to setup the usual suspects for scan tools to be performed in a scoped manner to satisfy the need for checked boxes after an operator spends some time getting up close and personal with the target system. Those type of attacks are going to reveal more information about user training (looking at Joe User with important\ passwords.docx in My\ Documents) than simple network scans are likely to.
I wonder what the qualifications are these days for a pen tester at a commerical company...
I'm not really surprised at that reaction.
Most people are looking for someone to perform a cover-your-arse paperwork exercise. By paying someone to port-scan their network, they can say "we receive regular security audits".
The fact that they haven't done a proper penetration test is immaterial.
"our site can't be hacked, it has an SSL cert!"