How I Hacked a Bank and Made 40 Bucks
golemtechnologies.com
golemtechnologies.com
Here's my take: if he is charging $7, $10, $40, whatever, he's running automated scans. If the customer is suggesting they'd be willing to pay $10k, they are most likely under the impression this is a real, full-fledged pen-test. That is a massively dangerous assumption. A real pen-test is not just some process you kick off and walk away. It involves real investigation, testing, and analysis. Charging $7, $40, would bankrupt a tester.
So why not charge $0?
If you love your customers, crank the price up - that'll encourage them to actually listen to the results you give them.
They simply don't care about the security of their customers because they have no incentive to.
I get that security is hard, but in this specific case, they knew about a hole and left it open for two months. That's negligence.
And to say that they don't care about security is wrong. Generally, small financial institutions like this are scared to death about security breaches, but in many cases, they simply don't have the expertise to properly assess and deal with them. The example of the calendar application is just one example.