RE: Email Pen-testing

From: Reava, Jeffrey (jeffrey.reava_at_pfizer.com)
Date: 03/23/04

  • Next message: Golomb, Gary: "RE: Evading inline security devices? (was: Evading IDS?)"
    To: Rob Shein <shoten@starpower.net>, "R. DuFresne" <dufresne@sysinfo.com>, Kevin <kevin@kevincomputers.com.sg>
    Date: Tue, 23 Mar 2004 11:18:13 -0500
    
    

    Great point. I would also add that at the end of the day, the company
    being tested has a very practical assessment of whether they are an
    "easy" or "hard" target, (ideally) based on the full range of attack
    choices available. It seems though that the bounds of pen testing are
    defined more in terms of what the company being tested is willing to
    consider correcting, rather than what the tester is able to exploit.

    >>>>...You're not looking to resemble reality, and not just because the
    reality is a bad bad thing...it's not a level playing field, but that
    didn't start when the pen-tester notified the company; it started when
    the company hired them and promised not to prosecute them for breaking
    in :)

    ------------------------------------------------------------------------

    ---
    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.
    www.coresecurity.com/promos/sf_ept1
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    You're a pen tester, but is google.com still your R&D team?
    Now you can get trustworthy commercial-grade exploits and the latest
    techniques from a world-class research group.
    www.coresecurity.com/promos/sf_ept1
    ----------------------------------------------------------------------------
    

  • Next message: Golomb, Gary: "RE: Evading inline security devices? (was: Evading IDS?)"

    Relevant Pages

    • Re: nmap shows open UDP port 113
      ... the actual packets themselves. ... > Now you can get trustworthy commercial-grade exploits and the latest ... > techniques from a world-class research group. ...
      (Pen-Test)
    • SV: Honeypot detection and countermeasures
      ... Considering that a honeypot is either not really rootable or is very ... > the tools and techniques of that particular pen test group. ... You're a pen tester, but is google.com still your R&D team? ... world-class research group. ...
      (Pen-Test)
    • RE: Oracle DB Audity
      ... There is a freeware toolkit for Oracle included in Red Hat 9. ... Now you can get trustworthy commercial-grade exploits and the latest ... techniques from a world-class research group. ...
      (Pen-Test)
    • Re: Cross Site Tracing examples?
      ... > Latest attack techniques. ... > You're a pen tester, but is google.com still your R&D team? ... > world-class research group. ...
      (Pen-Test)
    • RE: Sarca rainbow tables on-line cracking service
      ... If anybody else is working on these Rainbow tables, ... Now you can get trustworthy commercial-grade exploits and the latest ... techniques from a world-class research group. ...
      (Pen-Test)