I have both done pentests and received pentest reports. My observation is that the perceived severity often varies between the tester and the customer.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    14 days ago

    Even the potential threat wank they add to low severity stuff is ridiculous.

    Finding: device responding to ping requests.
    Severity: Low.
    Threat: Using timing attacks and response analysis an attacker could derived the devices operating system.

    • exu@feditown.com
      link
      fedilink
      English
      arrow-up
      9
      ·
      13 days ago

      The hacker might shame you for using Windows Server on a public forum!

      /s