As a penetration tester and long-time security professional, Sumit ‘Sid’ Siddharth is a big believer in the importance of practicing exploitation to gain better insight about vulnerabilities.
“The only way you can understand the true impact of vulnerabilities is by practicing exploitation. Even vulnerability identification goes hand in hand with exploitation,” says Siddharth, founder of NotSoSecure and a frequent Black Hat speaker and trainer. “Sometimes identifying the vulnerability is really difficult and its only when you know advanced exploitation techniques that you can do so. In my experience pen testing for ten years now, the biggest takeaway is that these two things feed into each other.”