Re: Security Audit

From: Phil Cracknell (phil@orthus.com)
Date: 09/13/01


Message-ID: <00cc01c13c97$d49ef500$0c00a8c0@jedi>
From: "Phil Cracknell" <phil@orthus.com>
To: <pen-test@securityfocus.com>
Subject: Re: Security Audit
Date: Thu, 13 Sep 2001 22:05:27 +0100


<SNIP>
> > Other problem can be also giving away
> > models and methods, because there are many
> smartasses that are just looking
> > after knowledge to do the job themselfs.
>

We have a methodology and would not hesitate in giving it to our clients, we
do so regularly, and we also abstract from this a detailed test plan for
them. These documents allow for some form of measurement in all of this and
as a result if a cowboy tries to sell them a $500 remote scan they have
something to compare it too.

The 'right' sort of client will have already identified that doing the job
themselves is not the right approach I would hope, regardless of how smart
their ass is.

Rgds

Phil
CTO - Orthus
www.orthus.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: ethics of approaching vulnerable prospective clients
    ... ethics of approaching vulnerable prospective clients ... Of interest especially are clients with wireless networks. ... site security, web application security etc. ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Dhcp security
    ... Setting up a 802.1x wired network requires: ... vendors, including Cisco, provide solutions to ensure that only properly ... trust agent collects security state information from multiple security ... software clients, such as anti-virus clients, and then communicates this ...
    (Focus-Microsoft)
  • Re: [Full-Disclosure] SSH vs. TLS
    ... > frowned upon by network ops and security. ... > - There must be a secure means by which all server keys are distributed to ... > appropriate ssh clients. ... > servers from using expired keys. ...
    (Full-Disclosure)