lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed Jan 18 17:15:18 2006
From: Valdis.Kletnieks at vt.edu (Valdis.Kletnieks@...edu)
Subject: Vulnerability/Penetration Testing Tools 

On Wed, 18 Jan 2006 08:13:05 CST, "Madison, Marc" said:
> H D, my apologize.  My FD emails were out of order, and I took your
> response out of context.  If your looking for a script that will combine
> MetaSploit, and Nessus then BidiBLAH will work.  Still for $10 grand I
> would suggest taking a scripting class at your local college so you can
> make your own BidiBlah.
> 
> Math:
> BidiBLAH:				$10,000
> College scripting class:		$350
> 
> The knowledge you'll gain for ever, priceless.

Something to keep in mind however - many people make that comparison, and
don't calculate the *TOTAL* cost.

If your developer is getting paid $60K/year, the *encumbered* cost (benefits,
office, etc) is close to twice that.  And if he's writing an in-house BidiBLAh,
that's time he's *not* writing stuff you *can't* buy off-the-shelf.
As a result, it breaks out as:

BidiBLAH:         $10,000

scripting clss:	     $350
6 man-weeks time: $15,000

OK? Got that?  Suddenly doesn't look like such a good deal, does it?  Maybe
you *should* just buy BidiBLAH, and have that guy coding that custom interface
between two in-house systems instead....

(And don't say "I only pay my developer $30K, so he can take 2 man-months to
do it" - the kind of developer you can keep for $30K is probably going to take
a lot more than twice as long as the $60K developer.....)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060118/bc286484/attachment.bin

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ