Skip to content

Comment on The World's Worst Penetration Test Report by #ScumbagPenTester

Comments

Sadly, relative to what I've seen, the examples here really aren't that bad. There are plenty of outfits based right here in the US who will happily sell you the output of a default scan from an outdated version of Nessus.

Also, you've not seen cut-n-paste, search-and-replace garbage until you've had to sift through the mountain of responses to a public sector RFP.

My best theory is that there are a large number of companies which simply shotgun shoveled together lowball responses to every posting. The lowball number virtually guarantees consideration and people who either don't really understand what they're procuring or don't actually read the responses let the stuff slip through.

I always made a point of requesting that the companies which submitted crap like that be banned from future solicitations - it never worked.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.