RE: How much do you disclose to customers?

From: Kinnane, Scott (Scott.Kinnane_at_ISATechnologies.com)
Date: 12/19/03

  • Next message: Gary Everekyan: "RE: How much do you disclose to customers?"
    Date: Fri, 19 Dec 2003 11:39:20 +0800
    To: <pen-test@securityfocus.com>
    
    

    I'd explain to the customer that in a real security attack, you don't
    know the source of the attack when it starts, so you need to simulate as
    real a situation as possible. The logs would come in handy as you could
    offer that as proof of what was coming from you.

    At least if they (including technical staff) know a time when you are
    doing the test, they can be prepared for consequences and as you say,
    ignore your attempts. I know this contradicts my previous point, but
    hey...

    Put it this way: if I were the customer, I'd rather know that my
    security measures are so thoroughly tested by your tests that they are
    as bullet proof as possible.

    scott

    > -----Original Message-----
    > From: Alfred Huger [mailto:ah@securityfocus.com]
    > Sent: Friday, 19 December 2003 4:14 AM
    > To: pen-test@securityfocus.com
    > Subject: How much do you disclose to customers?
    >
    >
    >
    >
    > I am posting this for a user who is having difficulty posting
    > directly to the list. Please reply to the list.
    >
    > -al
    >
    >
    > To: Joe P <joe_nasdaq@yahoo.com>
    > Cc: pen-test@securityfocus.com
    > Subject: Re: How much do you disclose to customers?
    >
    >
    > On Tue, 16 Dec 2003, Joe P wrote:
    >
    > > Hi everyone,
    > >
    > > I have a question on customer disclosure. Is it wise to tell the
    > customer which IP addresses you'll be
    > using before starting pen tests?
    > >
    > > Cons for Telling:
    > > I was thinking that if you did tell them you may get an
    > over zealous,
    > insecure admin that just sets up a
    > filter to block you out to make him/herself look good.
    > >
    > > Pros for Telling:
    > > 1) if you don't tell them your IP address they may think your doing
    > testing when in actuallity it's someone
    > else (ie: a true cracker trying to break in).
    > > 2) Audit trail reasons - if you trip up an IDS while doing testing
    > > they
    > can ignore those alarms.
    > >
    > > Also, how do testers handle multiple IP addresses? Is there any
    > > benefit
    > to doing it from multiple IP
    > addresses??
    > >
    > > How do testers distribute a test amongst multiple people?
    > >
    > > Lastly, do you keep logs of tests performed just to cover yourself?
    > (Ie: "Our server crashed on Saturday,
    > it must have been something you did!!"")
    > >
    > > thanks ahead of time,
    > > Joe
    > >
    > >
    > >
    >
    > Alfred Huger
    > Symantec Corp.
    >
    > --------------------------------------------------------------
    > -------------
    > --------------------------------------------------------------
    > --------------
    >
    >

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Gary Everekyan: "RE: How much do you disclose to customers?"

    Relevant Pages

    • How much do you disclose to customers?
      ... On Tue, 16 Dec 2003, Joe P wrote: ... > I have a question on customer disclosure. ... how do testers handle multiple IP addresses? ...
      (Pen-Test)
    • Re: Please help with a serious issue
      ... User 1 selects customer 1. ... The credit card table is filtered to that account ... What i basically need to know is how to allow multiple users to use the same ... Customer Shipping - Holds all possible shipping addresses for each client. ...
      (borland.public.delphi.database.ado)
    • Re: GIMUNZIP failure
      ... Many shops have multiple ... You can even order multiple java versions with ServerPac. ... the customer could be supporting multiple ...
      (bit.listserv.ibm-main)
    • Re: Outlook opens all attachments.
      ... > in fax viewer opens the pic from my temporary internet files. ... > we asked the customer to delete the temp folder and open one pic (the ... Maybe they are receiving in a TIF format that permits multiple images ... If one file format can permit multiple pages per file then I would ...
      (microsoft.public.outlook.general)
    • RE: How much do you disclose to customers?
      ... our IP's blocked by an IPS or by an unwitting admin. ... from multiple machines has its advantages, especially when given a class C or larger to split up the time. ... Logs are definitly important, one thing I wish automated scanners ... >> I have a question on customer disclosure. ...
      (Pen-Test)

  • Quantcast