logoalt Hacker News

ozimtoday at 6:35 AM1 replyview on HN

Because the proof is in the pudding.

Real pentests are about showing exploitation, merely enumerating vulnerabilities, that’s vulnerability scan and works on known vulnerabilities.

You can’t confirm a vulnerability by _not exploiting_ it, especially unknown one.


Replies

jdefr89today at 8:27 AM

You can still exploit a system and easily prove it via simply popping a shell or calc.exe or updating a database with a new entry, etc… They didn’t have to let it loose on the network. If that system was air gapped - problem solved.

show 1 reply