In this episode of Cyber Security Inside, Tom and Camille discuss the ins and outs of penetration testing with Director of Threat Research at Akamai Technologies, Moshe Zioni. Moshe has over 20 years of experience researching security and brings a lot of real-world insight to topics like:

• Red teams

• Bug bounty programs

• How penetration testing and red teams differ

• What the perimeters are around penetration testing

• White box, black box, and grey box penetration testing

• HackerOne and BugCrowd

• Responsible disclosure

...and more. Don’t miss it!

Here are some key take-aways:

• Internal validation and penetration testing are almost opposites in a sense. The former is designed to ensure the product is working the way it should when used the way it’s meant to be used. You’re limited to a finite set of actions. The latter is designed to see what happens when you introduce the unexpected or unintended into the mix.

• A good QA person will always ask ‘What will happen if I do that? How can I crash the system?’. The difference in penetration testing and adversarial research is that the questions and curiosity won’t end there.

• Red teaming and penetration testing differ in that, with red teams, the company knows it’s being attacked and is looking to detect the attack while it’s happening. With penetration testing, the system is being tested individually, sometimes with firewalls and other security parameters turned off.

• Penetration testing may be white box, black box, or grey box. With white box, the person doing the penetration testing will be given any needed details regarding the technology and how the product works – both front end and back end. With black box, they’ll be given nothing, not even a footprint to the server or any permissions. And with grey box penetration testing, the amount of information provided will be somewhere in between.

• For first time penetration testing with a limited time frame, the recommendation is to go with white box, so you get a deeper, more useful and comprehensive report.

•Facebook just dropped out of HackerOne and started their own bug bounty program, which is now the biggest in the world.

• More and more companies are joining circles like HackerOne and BugCrowd, and their security is benefiting from that engagement.

Some interesting quotes from today’s episode:

“The breaking apart is not the goal. The goal is to see what will happen in erroneous input. And the next step, the really Holy Grail, is how can we defend against those kinds of attackers?”

“It’s been validated. That basically means the product is working the way you expect it to work. So you test things that are, sort of, things that the machine is supposed to do. In the security side, it's almost the opposite. You do things that are expressly not expected.”

“If you have two weeks or one month of man time to do this work, the question is, how effectful will it be for a team or a single person to do this penetration testing work for a week or two? Which, let's remember that a real attacker will not have this limitation.”

“If it’s the first time that you are doing any kind of penetration testing, the general recommendation will be go with a big white box. Because you want to have a 360 of your systems and you don't want to have just a shallow report on what can be seen from the outside, from someone that spends two weeks on your website with no real intention or no real realization of what he's looking for.”

“You can't do a denial of service, which are attacks that are trying to crash down those systems, for example, especially production systems. That's very dangerous for a penetration testing to do…Phishing attacks or social engineering attacks are also out of the question. To involve any employees of the companies is also out of the question for penetration testing.”

“Intentionally, some red teaming are also involving either physical attacks, meaning someone that gets into the building, or trying to social engineer their way through phone and to get some passwords, maybe even to try to do some phishing attacks and even exploitation in terms of malware. But those are the extreme cases of red teaming.”

“If you are on a bug bounty program, you are mature enough in terms of security posture to say, ‘I know of my basic bugs and I'm fixing them. Please help me find the really nasty ones.’ It's something that really signals what kind of company you are in terms of security.”