Главная
Study mode:
on
1
Introduction
2
What is a Pentest
3
External vs Internal
4
Pentest Team
5
Engagement
6
Security
7
scoping call
8
system
9
report
10
walkthrough
11
internal systems
12
developer shop
13
final reports
14
easy to find issues
15
business logic flaws
16
how do you optimize
17
checklists
18
evangelize
19
no more fancy tools
20
easy to use
21
what is hunter
22
what is hunter not
23
SSL Versions
24
ILook Architecture
25
Frontend UI
26
HTTP endpoint
27
Local host
28
Test Site
29
Security Headers
30
MidLevel Rating
31
Headers
32
Policy
33
Scoring Model
34
CSP Policy
35
Cipher List
36
Legacy Applications
37
Pentest Results
38
Impact of Prereqs
39
More Slides
40
Future Plans
41
Outro
Description:
Explore the optimization of pentesting resources in this APPSEC Cali 2018 conference talk by Kiran Shirali, Senior Security Engineer at eBay. Learn about Hunter, an open-source tool developed to grade websites and REST endpoints for low-risk security issues. Discover how eBay reduced pentesting budget by 10-15% by implementing Hunter as a precursor to full pentests. Gain insights into the tool's grading system, its position between minimal security checks and comprehensive SDLC processes, and how it can benefit both managers and pentesters. Understand the journey behind Hunter's creation, its architecture, and scoring model. Ideal for security professionals looking to streamline their pentesting processes and allocate resources more efficiently.

Optimize Your Pentesters Time

OWASP Foundation
Add to list
0:00 / 0:00