October 13, 2023By TozettaPentest

Tozetta Hackers - 1st Place at Hâck the Hague

Tozetta, a Dutch company specialized in pentesting, has won the second edition of Hack The Hague.

On October 2nd, the second edition of ''Hack The Hague'' took place in The Hague. This hacking event is an initiative of the municipality of The Hague to improve cybersecurity in the city. During the event, teams of hackers set out to find vulnerabilities in the software and hardware of the municipality of The Hague.

A team including two Tozetta employees, Ian van der Wurff and Wout van der Ploeg, won the Hack The Hague event with the 'most sophisticated hack'! The team managed to find and exploit a critical vulnerability in one of the municipality of The Hague's websites.

Tozetta's pentest quality

This win is a great recognition of the quality of the pentests Tozetta delivers. As a specialist in ethical hacking, Tozetta operates in a niche market. Pentesting, also known as penetration testing, is a simulation of an actual hack, in which an organization's software and systems are checked for vulnerabilities by an ethical hacker.

By finding and exploiting vulnerabilities, a pentester can provide insight into how vulnerable an organization is to attacks. These vulnerabilities are highly valuable to the client, who can then remediate them!

Recognition for Tozetta's ethical hackers

The win by the Tozetta team members shows that they have the expertise and experience to find and exploit complex vulnerabilities. This is an important quality for a pentester, as it demonstrates that the pentester is able to truly test an organization for its vulnerabilities. On behalf of Tozetta, we congratulate our team members on this great recognition and accompanying prize!

What does an ethical hacker actually do?

During the event, Ian van der Wurff gave an interview about what an ethical hacker actually does. A question we still get asked often at Tozetta. An (ethical) hacker uses their knowledge and expertise to find mistakes (vulnerabilities) in people or in software and systems.

Once the vulnerabilities have been identified, the hackers do everything they can to use (exploit) these vulnerabilities. This allows the hackers to carry out actions that shouldn't be possible, or to access data they are not authorized to access. In the latter case, this concerns a data breach, something many companies want to prevent.

So what is the difference between an (ethical) hacker and a cybercriminal? A cybercriminal uses their knowledge and expertise to deceive people or to exploit vulnerabilities in software and systems for personal gain.

Watch the video of Lead Pentester Ian van der Wurff below!

https://www.youtube.com/watch?v=St_oSLxYemc

''A Great Experience with Challenges'' - Wout

Tozetta ethical hacker Wout van der Ploeg is only 16 years old. Yet Wout is an important part of the team and made a huge contribution to the win. Below, Wout shares more about his experience during this event!

As an ethical hacker at Tozetta, I recently took part in Hack The Hague. It was a great experience, but there were also some challenges. One challenge was the scale of the event. With so many websites to choose from, it was difficult to determine which website was vulnerable. This made it hard to dig deep into the vulnerabilities of a specific website. Another challenge was networking and connecting with other hackers. This event offers a valuable opportunity to connect with other people in this field, but it can also be overwhelming. In addition, there was an informal drink after the event where we could share our findings and information, which further promoted the exchange of knowledge and experiences. I have a few takeaways for the next edition of Hack The Hague. Managing the scope was a challenge, given the scale of the event. It's easy to lose track and no longer know which websites have already been tested and which haven't. All in all, Hack The Hague was a great experience. I learned a lot and met new people.

Wout van der Ploeg, Ethical Hacker at Tozetta

What is pentesting?

Pentesting is a form of security in which a company or organization is checked for vulnerabilities by a pentester. Pentesting can be carried out in various ways, depending on the organization's activities and the systems it uses.

A pentester will first study the organization and the systems it uses. The pentester will then try to find vulnerabilities. This can be done in various ways, for example by using tools and techniques that are also used by malicious hackers.

Once a pentester has found a vulnerability, they will try to exploit it. This means the pentester attempts to use the vulnerability to gain access to sensitive information or to sabotage a system.

The results of a pentest are reported to the organization. This report contains information about the vulnerabilities found and recommendations for how these vulnerabilities can be resolved.

Why is pentesting important?

Pentesting is an important part of cybersecurity. By regularly conducting pentests, an organization can ensure that its systems and networks are properly secured.

Vulnerabilities can be exploited by hackers to gain access to sensitive information, sabotage systems, or even cause damage. Pentesting can help find and eliminate these vulnerabilities, reducing the chance of a successful attack.

of SMEs that get hacked go bankrupt within 6 months due to lost production time. 1 % is the average damage caused by a cyber incident. € 1 K of cyber incidents and data breaches are caused by human error. 1 %

Related articles