Skip to content

Comment on The World's Worst Penetration Test Report by #ScumbagPenTesterparent

Comments

They are probably using an automated testing tool of which there are many. These tools are all pretty dumb and the typically end up running all the tests on all the machines w/o taking into account prior knowledge like, "This is a windows server". These tools end up returning a bunch of useless information that a knowledgeable person then needs to sort through to confirm each potential problem.

The issue arrises when someone takes what pops out of the scanner as gospel instead of investigating if it is true or a false positive.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.