@sawaba It must be. Ones I have talked to for *years* have basically had a 100% success rate on pentests that were scoped decently.
-
-
@attritionorg It depends on what we call success. If you gain access to a system, but couldn't get CCNs (the goal), did you succeed? -
@sawaba Never heard of that happening. Testers I know have popped card data on "PCI certified" systems every time they tried. -
@attritionorg That's not my personal experience at all, especially with retail.
End of conversation
New conversation -
-
-
@attritionorg We have to redefine success in pentesting. Getting shell rarely hurts the company, but we count it toward this "100% success".Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.