WTF, OF COURSE WE DO WEB APP PEN TESTING
Dave G. | June 4th, 2008 | Filed Under: Matasano, Navel Gazing
It boggles my mind, but we get a fair amount of people asking us if we do web application penetration testing, or if we only do the “interesting stuff”. I think there are two reasons for this:
- The first is, our website just doesn’t explain what we do very well.
- Our blog focuses on the “interesting stuff”.
A dirty little Matasano secret is:
We not only do a lot of web app pen testing, but we actually like it.
I know, it’s crazy, isn’t it? People who can spend a day in a disassembler without bleeding from their eyes aren’t supposed to enjoy testing software as open as websites. But you know what? You have to be engaged to turn in a good penetration test, and if you can’t engage on a web app project, you might be in the wrong business. We like breaking software. The web is no different.
We’re lucky to get diverse projects, and what we find is, the skills you use on them cross-pollinate constantly. For instance:
- Your software protection project involves lots of block crypto, which you take with you to bust up a web site that uses AES ECB tokens.
- Or, in the reverse, web pen testing teaches you to think about how sessions are managed, which you take to a binary management protocol and score auth bypass with.
The fact is, there are security disciplines that web app developers have matured far more than shrink wrap or embedded developers like session management, single sign-on, and authorization systems and there are disciplines where the C coders are still the thought leaders, like crypto and software protection. If you ignore either, you fall behind.
So, to answer the question, one last time…
Yes, we do web application penetration testing. And we are horrifyingly good at it.


Michael H. Buselli
June 5th, 2008 8:54 amAnd here I thought web application penetration testing was included as part of the “interesting stuff” anyway.
Dave G.
June 6th, 2008 7:17 pmI agree. But i also understand that many readers of our blog come here to read about custom protocol/reversing types of posts.
mac
June 9th, 2008 7:54 amGreat, how about writing something about webapp testing? I think many would like to know how you genereally approach this?
PaulM
June 9th, 2008 11:06 amAll this time I thought you guys sold firewall management software and food dehydrators…
Dave G.
June 9th, 2008 1:30 pm@mac:
will do.
@PaulM:
We don’t sell food dehydrators. But if you are looking for one, go with an Excalibur. For the product, check back here soon.
Leave a reply