Nytro Posted October 1, 2014 Report Posted October 1, 2014 How not to suck at pen testing John StrandDerbycon 2014 Godamitsomuch. How did printing a report from a vuln scan - ner qualify as a “pen test”? Why are your testers ignoring low and informational findings? In this presentation, John will cover some key components that many penetration tests lack, including why it is impor - tant to get caught, why it is important to learn from real attackers and how to gain access to organizations without sending a single exploit, and how to look for other attackers on the network. Additionally, John will show you how to bypass “all powerful” white listing applications that are often touted as an impenetrable defense. Via: How not to suck at pen testing - John Strand Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos) Quote