Setup Idea Do yourself a favor and order a free Penetration Test

Last updated
Sep 26, 2024
How it's used?
For home and private use
Operating system
macOS 15 Sequoia
Other operating system
Linux
On-device encryption
N/A
Log-in security
    • Hardware security key
Security updates
Allow security updates
Update channels
Allow stable updates only
User Access Control
Always notify
Smart App Control
On
Network firewall
Enabled
Real-time security
The pentest will test your security.
Firewall security
Other - Internet Security (3rd-party)
About custom security
What ever you have
Periodic malware scanners
KRT
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browser(s) and extensions
MS Edge
Secure DNS
Quad9
Desktop VPN
ProtonVPN
Password manager
Chrome's built-in password manager
File and Photo backup
Macrium Reflect
System recovery
Macrium Reflect
Risk factors
    • Browsing to popular websites
Computer specs
Asus Vivobook
Recommended for
  1. All types of users

Victor M

Level 12
Thread author
Verified
Top Poster
Well-known
Oct 3, 2022
573
You can do simple penetration tests on yourself. A pen test is more than a vulnerability scan. It uses hacking tools to simulate an attack. Penetration tests used to be an expensive endeavor requiring you to hire a pen test company and can span several days. However automation has caught up.

Much like testing your AV's detection capabilities with live malware, you want to detect what holes you have remaining after you have applied all your protections. It is termed 'offensive security'.

Intruder.io has a 7 day free trial allowing you do a test of your own ip and web presence. Just go to whatsmyip.org, copy the ip address and paste it into Intruder's site. And enter also your web page URL into the targets if you have any. If you want it to scan past your router/hardware firewall you have to install an agent onto your PCs. It gives you a PDF results download.




You need to provide a credit card to do the pen test. Just remember to delete the scheduled monthly test, and unsubscribe to their service when you have finished testing.

They also want a company email address, if you don't want to use yours, just use a free temporary email service and wait for the verification email.
 
Last edited:

tofargone

Level 4
Jun 24, 2024
174
Penetration test?

This sounds risky, will it hurt?

Do I do this at home or do I have to go to the doctors office?
 

BSONE

Level 2
Feb 17, 2024
71
Humour aside, does anyone have an opinion on this service. I am comfortable using a credit card for the trial as one of my my credit providers has a one time use disposable card option.
 
  • Like
Reactions: simmerskool

Victor M

Level 12
Thread author
Verified
Top Poster
Well-known
Oct 3, 2022
573
My opinion of intruder.io is that it is good.

The good thing is that it found up to date things, as I only did an upgrade a day before; and it found the missing update.

And it also prioritize the issues it finds into low, medium and high. So you will know which to fix first.

Also it found coding security omissions on our web presence, and explained why the fixes are necessary and gave attack methods that would exploit them.

It also detected our web application firewall and stopped the test, asking us to whitelist intruder.io.
 
Last edited:

BSONE

Level 2
Feb 17, 2024
71
Tested on Joe Biden: Failed Swiss Emmental cheese stress test, with lots of holes and air bubbles reported.
Tested on Donald Trump: Unable to conclude test as behind Paywall. Likely to pass though as protected by Thomas the Tank Engine Uber advanced security secret sauce technology ™
 
  • HaHa
Reactions: n8chavez

Victor M

Level 12
Thread author
Verified
Top Poster
Well-known
Oct 3, 2022
573
Well, what one white hat hacker knows is different from what another knows. So pen tests are subjective. But when we take all the white hats' public domain-ed and CVE'd and POC'd attacks and test them on ourselves we do gain some positive protection, do we not?
 
  • Like
Reactions: simmerskool

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top