Re: Penetration Testing/Vulnerability Assessment

From: Emre Yildirim (emre@sgi.asper.org)
Date: 09/08/01


Message-ID: <3B99A0A7.7070200@sgi.asper.org>
Date: Fri, 07 Sep 2001 23:37:59 -0500
From: Emre Yildirim <emre@sgi.asper.org>
To: Julias P <pjulias@cbz.co.zw>
Subject: Re: Penetration Testing/Vulnerability Assessment

Julias P wrote:

> I have been reading about the reponses on "Security Audit" and I have learnt
> quite a lot. I am currently working on implementing a security policy for my
> organisation, before we hire some security consultant for review. I think

> vulnerability assessment goes hand in hand with penetration testing.

Take a look at this:
http://www.securityfocus.com/focus/basics/articles/policies.html

> What about free tools I could use for penetration
> testing.

http://www.securityfocus.com/tools

nmap (www.insecure.org) is also very useful.

-- 
Emre Yildirim <emre@asper.org>
GPG KeyID 0xF9E4A1D1 (keyserver.pgp.com)

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: MORE: Tools for Detecting Wireless APs - from the wire side.
    ... I find it amazing -- the question CLEARLY states "from the wire side", ... Subject: MORE: Tools for Detecting Wireless APs - from the wire ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: escalating IUSR to admin rights via unicode and iis4
    ... 6- Try a command line net scan that can be uploaded to the web server ... any TCP/IP connections from your host through a middle host to ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)

Quantcast