[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <200601181714.k0IHETZR027346@turing-police.cc.vt.edu>
Date: Wed Jan 18 17:15:18 2006
From: Valdis.Kletnieks at vt.edu (Valdis.Kletnieks@...edu)
Subject: Vulnerability/Penetration Testing Tools
On Wed, 18 Jan 2006 08:13:05 CST, "Madison, Marc" said:
> H D, my apologize. My FD emails were out of order, and I took your
> response out of context. If your looking for a script that will combine
> MetaSploit, and Nessus then BidiBLAH will work. Still for $10 grand I
> would suggest taking a scripting class at your local college so you can
> make your own BidiBlah.
>
> Math:
> BidiBLAH: $10,000
> College scripting class: $350
>
> The knowledge you'll gain for ever, priceless.
Something to keep in mind however - many people make that comparison, and
don't calculate the *TOTAL* cost.
If your developer is getting paid $60K/year, the *encumbered* cost (benefits,
office, etc) is close to twice that. And if he's writing an in-house BidiBLAh,
that's time he's *not* writing stuff you *can't* buy off-the-shelf.
As a result, it breaks out as:
BidiBLAH: $10,000
scripting clss: $350
6 man-weeks time: $15,000
OK? Got that? Suddenly doesn't look like such a good deal, does it? Maybe
you *should* just buy BidiBLAH, and have that guy coding that custom interface
between two in-house systems instead....
(And don't say "I only pay my developer $30K, so he can take 2 man-months to
do it" - the kind of developer you can keep for $30K is probably going to take
a lot more than twice as long as the $60K developer.....)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060118/bc286484/attachment.bin
Powered by blists - more mailing lists