Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Penetration Testing is Stupid - BsidesSF 2013
Search
Brett Hardin
February 25, 2013
Technology
2.3k
2
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Penetration Testing is Stupid - BsidesSF 2013
Brett Hardin
February 25, 2013
More Decks by Brett Hardin
See All by Brett Hardin
Building Your House on Sand
bretthardin
2
1.5k
Bad Version of Builders vs. Breakers
bretthardin
1
94
Builders vs. Breakers - AppSec 2012
bretthardin
2
1.5k
Security the Wrong Way
bretthardin
2
270
BSidesSanFrancisco2011 - Misdirection: The Rise and Fall and Rise of Regulatory Compliance
bretthardin
1
260
Security? Who Cares! - Privacy is Dead
bretthardin
1
210
OWASP - Top 10
bretthardin
0
1.1k
Other Decks in Technology
See All in Technology
積み重なった技術負債への挑戦 〜初手としての全社ゴト化〜
techtekt
PRO
0
730
家のリアーキテクト・リファクタリング
suguruooki
0
150
Snowflakeのコスト最適化を支えるアーキテクチャ設計
ktatsuya
1
1.6k
すぐできる衛星通信対応 あとは山奥に行くだけ
tatetate55
0
120
Sigmaで作る業務アプリ
kazushiro_honma
0
140
あるけみー式LTスライド作成術
alchemy1115
1
210
GoCon2026 - Open Source, Open World
sanposhiho
4
4.2k
synctest時代のhttptest Go 1.27で変わるHTTPサーバテストの裏側 / go conference2026 synctest and httptest
budougumi0617
1
2.8k
2026/09/10 Spring Bootから Jakarta EE/MicroProfileへの移行
megascus
0
360
Snowflakeで実現する全社横断の顧客の声(VOC)分析・活用基盤@Snowflake World Tour Tokyo 2026
yuto16
0
210
Gitは怖い?共有ワークスペースから始めるSnowflakeチーム開発
coco_se
0
210
AI 時代のスタートアップエコシステ厶から考究する技術的負債との向き合い方
m3m0r7
PRO
2
1.5k
Featured
See All Featured
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.6k
Dominate Local Search Results - an insider guide to GBP, reviews, and Local SEO
greggifford
PRO
0
330
実際に使うSQLの書き方 徹底解説 / pgcon21j-tutorial
soudai
PRO
202
76k
How to build a perfect <img>
jonoalderson
1
6k
Leo the Paperboy
mayatellez
9
2.3k
Darren the Foodie - Storyboard
khoart
PRO
3
3.9k
Effective software design: The role of men in debugging patriarchy in IT @ Voxxed Days AMS
baasie
0
520
ラッコキーワード サービス紹介資料
rakko
1
4.9M
The Illustrated Children's Guide to Kubernetes
chrisshort
51
53k
How to make the Groovebox
asonas
2
2.4k
Odyssey Design
rkendrick25
PRO
2
800
The Art of Programming - Codeland 2020
erikaheidi
57
14k
Transcript
Penetration Testing is stupid
Brett Hardin @miscsecurity
None
None
pentesters
Why Who Where When What PENETRATION TESTING Why Who Where
When What
Why Who Where When What PENETRATION TESTING What
Audience Participation Educated Guess?
A live test of the effectiveness of security defenses through
mimicking the actions of real-life attackers. ISACA
test security defenses
mimicking real-life attackers
MIMIC THE REAL
Gunter Ollmann of Damballa on Real Attacks
Submit CV 2000
USB Keys 2005 2000
Buy the machine 2009+ 2005 2000
Penetration tests are unique
Penetration testers are friendly
Penetration tests don’t simulate attacks
Why Who Where When What PENETRATION TESTING Who
The Average Penetration tester
performed by
Jack Nicholson
I’M A PROFESSIONAL TRUST ME.
I’LL TRY ‘PASSWORD’
I’LL TRY ‘PA55WORD’
LET ME IN. PLEASE.
YOU WILL LET ME IN.
WE’RE FRIENDS
WHY CAN’T I GET IN?
LOOK, A WAY IN.
THEY WERE SO DUMB
I’M GONNA REDRUM HIM
pentesters
The average penetration tester
The average are common
The average are necessary
The average are cheap
The average are simple to copy
The average follow methodologies
The best penetration testers
The best are rare
The best invent new attacks
The best are expensive
The best are overkill
The best mimic the real
The average mimic tools
MIMIC THE REAL
MIMIC THE REAL
Why Who Where When What PENETRATION TESTING When
ATTACKS happen when you’re asleep
ATTACKS happen when you’re on vacation
ATTACKS happen when you have no budget
ATTACKS happen when during business hours
ATTACKS happen when you are not ready
ATTACKS happen when you are ready PENTESTS
Date&Time&Resources
None
Attackers aren’t limited by resources
MIMIC THE REAL
MIMIC THE REAL
Why Who Where When What PENETRATION TESTING Where
Rules of Engagement
Internet
Web Application only
On-site
Dialup
The Wi-fi’s
‘puters
News Flash
Attackers don’t care
Limits
Attackers aren’t limited by resources previously learned
Attackers aren’t limited by resources Revision
Attackers aren’t limited
Phone
MIMIC THE REAL
Why Who Where When What PENETRATION TESTING Why
Penetration testing isn’t important
Penetration testing isn’t important to most organizations
Penetration testing doesn’t secure you
Penetration testing tests defenses
required We’ve Convinced Everyone* it’s
TANGENT ALERT
Penetration Testers love to diss vendors
Penetration Testers are vendors
BACK TO YOUR REGULARLY SCHEDULED PROGRAM
Penetration testing proves two things
Penetration testing proves vulnerability One
Penetration testing proves vulnerability adjective One
Penetration testing identifies a few* risky issues Two
Penetration testing identifies a few* risky issues * Actual Results
may vary Two
known and unknown
new exploits aren’t needed
known exploits work
low-hanging fruit
expensive & rare New Exploits
MIMIC THE REAL
When pen testing isn’t stupid
No more defensive ideas
No more low-hanging fruit
Management wants to assess security controls
check&balance
Why Who Where When What < Attackers are unique
Why Who Where When What < Different attack methods
Why Who Where When What < Unlimited by time
Why Who Where When What No Rules of Engagement <
Why Who Where When What < Doesn’t protect you
Penetration Tests don’t mimic real attacks summary
Penetration Tests don’t secure you summary
Penetration Tests test your defenses summary
Thanks.
Brett Hardin http://bretthard.in