Re: Pen Testing for SMEs?

Harry Percival <[email protected]> Mon, 3 Jul 2023 18:48:08 +0100
Newsgroups gmane.comp.python.org.uk
Message-ID <CACFvh983tKVMT-9WkMtr0YTFH2twZgOeYfXtPLmd8dck5YD=rg@mail.gmail.com>
--===============1201925498471606481==
Content-Type: multipart/alternative; boundary="00000000000093cd2105ff98c59d"

--00000000000093cd2105ff98c59d
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Have you considered bug bounty programmes? I think we used HackerOne back
in the day and got a few actionable fixes out of it, without ever spending
too much money.

Iirc we'd pay out like $50 for little things that were arguably not real
vulns but just missing best practices (rate limiting password reset
requests was an example iirc? Bit worried someone will jump on me saying
how insanely important that is lol) - the kinds of things you can find with
an automated tool and minimal actual effort from the pentester -- and 10x
that (or more? Cant remember. In anycase i'm guessing H1 have suggested
payouts) for "real" bugs with PoC.

You did have to deal with a bit of spam but overall it was worth it.

Hp



On Mon, 3 Jul 2023, 14:22 SW, <[email protected]> wrote:

> I can also add https://istormsolutions.co.uk/ - I have a friend who
> works there, though I've not used their services myself.
>
> Thanks,
> S
>
> On 03/07/2023 15:03, Gautier Hayoun wrote:
> > Hi William,
> >
> > I have dealt with Callum at Sencode (https://sencode.co.uk/) recently.
> > They are a small company based in the UK, and I was perfectly
> > satisfied when their pen test of a Django web application.
> >
> > Best,
> >
> > Gautier
> >
> > On 03/07/2023 13:55, William Mayor wrote:
> >> Hi!
> >>
> >> This isn=E2=80=99t exactly on topic, but I=E2=80=99m running out of le=
ads on this
> >> one. Any help is appreciated :)
> >>
> >> I=E2=80=99m looking for a penetration/security testing company that ca=
n help
> >> me with a product that we=E2=80=99re building. It=E2=80=99s an API (wr=
itten using
> >> FastAPI, so there is a python link in here :) ), with web and native
> >> app front ends.
> >>
> >> I=E2=80=99d like to have some kind of certified test conducted, to fin=
d all
> >> the security edge cases that I=E2=80=99ve undoubtably missed.
> >>
> >> We=E2=80=99re a small company (a social enterprise), so our budget isn=
=E2=80=99t great.
> >>
> >> So my question is, does anyone have any recommendations for a pen
> >> testing company that could help?
> >>
> >> Thank you!
> >>
> >>
> >> _______________________________________________
> >> python-uk mailing list
> >> [email protected]
> >> https://mail.python.org/mailman/listinfo/python-uk
> > _______________________________________________
> > python-uk mailing list
> > [email protected]
> > https://mail.python.org/mailman/listinfo/python-uk
>
> _______________________________________________
> python-uk mailing list
> [email protected]
> https://mail.python.org/mailman/listinfo/python-uk
>

--00000000000093cd2105ff98c59d
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Have you considered bug bounty programmes? I think we use=
d HackerOne back in the day and got a few actionable fixes out of it, witho=
ut ever spending too much money.<div dir=3D"auto"><br></div><div dir=3D"aut=
o">Iirc we&#39;d pay out like $50 for little things that were arguably not =
real vulns but just missing best practices (rate limiting password reset re=
quests was an example iirc? Bit worried someone will jump on me saying how =
insanely important that is lol) - the kinds of things you can find with an =
automated tool and minimal actual effort from the pentester -- and 10x that=
 (or more? Cant remember. In anycase i&#39;m guessing H1 have suggested pay=
outs) for &quot;real&quot; bugs with PoC.</div><div dir=3D"auto"><br></div>=
<div dir=3D"auto">You did have to deal with a bit of spam but overall it wa=
s worth it.</div><div dir=3D"auto"><br></div><div dir=3D"auto">Hp</div><div=
 dir=3D"auto"><br></div><div dir=3D"auto"><br></div></div><br><div class=3D=
"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, 3 Jul 2023, 14:=
22 SW, &lt;<a href=3D"mailto:[email protected]">[email protected]=
</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:=
0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I can also add <a h=
ref=3D"https://istormsolutions.co.uk/" rel=3D"noreferrer noreferrer" target=
=3D"_blank">https://istormsolutions.co.uk/</a> - I have a friend who <br>
works there, though I&#39;ve not used their services myself.<br>
<br>
Thanks,<br>
S<br>
<br>
On 03/07/2023 15:03, Gautier Hayoun wrote:<br>
&gt; Hi William,<br>
&gt;<br>
&gt; I have dealt with Callum at Sencode (<a href=3D"https://sencode.co.uk/=
" rel=3D"noreferrer noreferrer" target=3D"_blank">https://sencode.co.uk/</a=
>) recently. <br>
&gt; They are a small company based in the UK, and I was perfectly <br>
&gt; satisfied when their pen test of a Django web application.<br>
&gt;<br>
&gt; Best,<br>
&gt;<br>
&gt; Gautier<br>
&gt;<br>
&gt; On 03/07/2023 13:55, William Mayor wrote:<br>
&gt;&gt; Hi!<br>
&gt;&gt;<br>
&gt;&gt; This isn=E2=80=99t exactly on topic, but I=E2=80=99m running out o=
f leads on this <br>
&gt;&gt; one. Any help is appreciated :)<br>
&gt;&gt;<br>
&gt;&gt; I=E2=80=99m looking for a penetration/security testing company tha=
t can help <br>
&gt;&gt; me with a product that we=E2=80=99re building. It=E2=80=99s an API=
 (written using <br>
&gt;&gt; FastAPI, so there is a python link in here :) ), with web and nati=
ve <br>
&gt;&gt; app front ends.<br>
&gt;&gt;<br>
&gt;&gt; I=E2=80=99d like to have some kind of certified test conducted, to=
 find all <br>
&gt;&gt; the security edge cases that I=E2=80=99ve undoubtably missed.<br>
&gt;&gt;<br>
&gt;&gt; We=E2=80=99re a small company (a social enterprise), so our budget=
 isn=E2=80=99t great.<br>
&gt;&gt;<br>
&gt;&gt; So my question is, does anyone have any recommendations for a pen =
<br>
&gt;&gt; testing company that could help?<br>
&gt;&gt;<br>
&gt;&gt; Thank you!<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; python-uk mailing list<br>
&gt;&gt; <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"n=
oreferrer">[email protected]</a><br>
&gt;&gt; <a href=3D"https://mail.python.org/mailman/listinfo/python-uk" rel=
=3D"noreferrer noreferrer" target=3D"_blank">https://mail.python.org/mailma=
n/listinfo/python-uk</a><br>
&gt; _______________________________________________<br>
&gt; python-uk mailing list<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noref=
errer">[email protected]</a><br>
&gt; <a href=3D"https://mail.python.org/mailman/listinfo/python-uk" rel=3D"=
noreferrer noreferrer" target=3D"_blank">https://mail.python.org/mailman/li=
stinfo/python-uk</a><br>
<br>
_______________________________________________<br>
python-uk mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer=
">[email protected]</a><br>
<a href=3D"https://mail.python.org/mailman/listinfo/python-uk" rel=3D"noref=
errer noreferrer" target=3D"_blank">https://mail.python.org/mailman/listinf=
o/python-uk</a><br>
</blockquote></div>

--00000000000093cd2105ff98c59d--

--===============1201925498471606481==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
python-uk mailing list
[email protected]
https://mail.python.org/mailman/listinfo/python-uk

--===============1201925498471606481==--