Re: Limited vs full blown testing

From: Peter Wood (peterw_at_firstbase.co.uk)
Date: 06/24/04

  • Next message: pingywon MCSE: "Re: troubles with wireless pentest"
    Date: Thu, 24 Jun 2004 13:02:09 +0100
    To: pen-test@securityfocus.com
    
    

    At 09:27 23/06/2004 -0700, Toby Barrick wrote:
    >During my many years of pen testing one common thread when dealing with
    >customers has been the request to not perform any destructive or DOS type
    >testing. When I speak of DOS, I'm not talking about DDOS, I'm talking just
    >a single machine and the tests that can be accomplished with that machine.
    >IMHO abiding by that request is really short changing the customer and
    >skewing the results. Additionally a lot of companies don't want their
    >applications poked at either.
    >
    >What has been the experience of the members on this list? Do you just
    >gleefully accept the check and any limitations imposed on testing or do
    >you push for a "complete" suite of tests?

    We accept a brief excluding DoS attacks, as most clients just won't support
    DoS testing. However we include appripriate caveats in our report and
    continue to suggest they do these tests.

    regards
    Pete

    --------------------------------------------------------------------------------------------------------------------------------
    www.fbtechies.co.uk


  • Next message: pingywon MCSE: "Re: troubles with wireless pentest"

    Relevant Pages

    • Limited vs full blown testing
      ... customers has been the request to not perform any destructive or DOS ... When I speak of DOS, I'm not talking about DDOS, I'm ... talking just a single machine and the tests that can be accomplished ...
      (Pen-Test)
    • Whats going on with Microchip?
      ... Because of that risk I requested all our customers to review their ... Many of you listened to that genuine request ... an order with Microchip for the next 8 to 12 weeks of your ... are now finding it difficult to live with even 3 to 4 week lead-times. ...
      (comp.arch.embedded)
    • Re: Questions about Ada Core Technologies
      ... > to redistribute binaries (as long as they also redistribute the ... ACT may not _require_ that customers not give ... But they do informally request it. ...
      (comp.lang.ada)
    • Re: Stamps.com Warning
      ... Customers using PayPal MasterCard Debit Cards are seeing what they ... authorization to bill but does not bill the actual transaction. ... Stamps.com Postage Group ... requested and the duplicate request stamps.com sends is withdrawn from ...
      (alt.marketing.online.ebay)
    • Re: Stamps.com Warning
      ... Customers using PayPal MasterCard Debit Cards are seeing what they ... authorization to bill but does not bill the actual transaction. ... Stamps.com Postage Group ... requested and the duplicate request stamps.com sends is withdrawn from ...
      (alt.marketing.online.ebay)