Главная
Study mode:
on
1
Intro
2
Crisis of Confidence
3
MissionAccomplished
4
Weve gotten to a point
5
Lack of control
6
Risk exposure
7
Global financial crisis
8
Nothing happens
9
A simple quick test
10
The problem with InfoSec
11
Quick Kill
12
Pen Testers
13
Poll
14
One Zero Day
15
Zero Day Splits
16
You Never Need Zero Day
17
Why Do We Need Zero Day
18
Are Our Attackers Using Zero Day
19
Mass Vonage
20
Aurora
21
HBGary
22
Charlie Miller
23
Tauntaun
24
Attack a Mess
25
Quick Lessons
26
Browsers are the weakest link
27
Browsers dont show up on pen test report
28
Current version of Java
29
Attacking Java
30
Ignoring ZeroDay
31
ZeroDay for Everything
32
Arms Race
33
In intractable problem
34
Professional pen testers
35
How to get data out of networks
36
Squeezer
37
Leader
38
Sequel Injection
39
Classic Case
40
Coverage
41
Market for Lemons
42
Penetration Testing is Harmful
43
Why is Penetration Testing so Popular
44
Hill Climbing Problem
45
Pen Test Standard
46
Elevation of Privilege
47
App Testing
48
PaperBased Testing
49
Gamification
50
Opponents
51
Zero Day
52
Will it make pen tests less fun
53
Focus on the customers problem
54
Show how clever you are
55
Do we need to change
56
Were in this bad spot
57
Antivirus
58
Integrity
59
Reset
60
Outro
Description:
Explore a thought-provoking conference talk from the 44CON Information Security Conference that challenges conventional wisdom on penetration testing. Delve into Haroon Meer's presentation, which examines the potential drawbacks and limitations of current penetration testing practices. Gain insights into the crisis of confidence in information security, the overreliance on zero-day vulnerabilities, and the challenges faced by professional pen testers. Learn about the weaknesses in browser security, the importance of Java vulnerabilities, and the concept of "market for lemons" in penetration testing. Discover alternative approaches to security testing, including app testing, paper-based testing, and gamification. Reflect on the need for change in the industry and the importance of focusing on customer problems rather than showcasing technical prowess. This 47-minute talk offers a critical perspective on penetration testing and encourages security professionals to rethink their approaches to vulnerability assessment and risk management. Read more

Penetration Testing Considered Harmful

44CON Information Security Conference
Add to list
0:00 / 0:00