RE: Limited vs full blown testing

From: Martin Murray-Brown (Martin.Murray-Brown_at_derivco.com)
Date: 06/24/04

  • Next message: terrydunlap_at_netzero.com: "Re: troubles with wireless pentest"
    Date: Thu, 24 Jun 2004 11:22:05 +0200
    To: <pen-test@securityfocus.com>
    
    

    Heyas,

    I would recommend preparing a standard document detailing the tests (not
    a full test plan, something dumbed-down for the suits), and also
    detailing the pro's and con's of both doing the test, and NOT doing the
    test. That way the customer can make an informed decision as to what to
    do and what not to do.

    Then, if you make the possible consequences of NOT doing the test
    sufficiently scary, the customer is more likely to agree to actually
    doing a test.

    Also, it makes you look even more professional... just slap in document
    control and a fancy header :)

     - M

    -----Original Message-----
    From: Toby Barrick

    All,

    During my many years of pen testing one common thread when dealing with
    customers has been the request to not perform any destructive or DOS
    type testing. When I speak of DOS, I'm not talking about DDOS, I'm
    talking just a single machine and the tests that can be accomplished
    with that machine. IMHO abiding by that request is really short changing

    the customer and skewing the results. Additionally a lot of companies
    don't want their applications poked at either.

    What has been the experience of the members on this list? Do you just
    gleefully accept the check and any limitations imposed on testing or do
    you push for a "complete" suite of tests?

    Thanks in advance!

    T


  • Next message: terrydunlap_at_netzero.com: "Re: troubles with wireless pentest"

    Relevant Pages

    • Re: Form drom dos program will not "Full Screen" in XP as in 98 or
      ... > another' program at this time for the customer. ... > Thanks AMD ... Why would Microsoft spend any time with a problem in running a DOS ... money at all) and make a small partition for the older os. ...
      (microsoft.public.windowsxp.general)
    • Re: [opensuse] Ah, Sanity Returns to the Release Schedule
      ... 'privileged' customer was damn near impossible.... ... I rarely ran into a DOS program that wouldn't run ... Microsoft wanted to go straight for the 386, but IBM had this ... people went out and bought Windows ...
      (SuSE)
    • Re: Form drom dos program will not "Full Screen" in XP as in 98 or
      ... > Virtual machine would be to intensive for this machine. ... > Thanks AMD ... >>> I have had this problem before where a FORM from a dos program will ... >>> customer "could" live with it before. ...
      (microsoft.public.windowsxp.general)
    • Re: Batch file
      ... There is no DOS under Windows, there is only a Command Prompt. ... >> should work the same as %Userprofile%\Desktop\test.txt and the exit ...
      (microsoft.public.win2000.general)
    • Taking the plunge
      ... We have a machine controller program that is currently in DOS. ... windows code and take advantage of things like multi-threading. ... keystrokes, serial I/O, and if I get really ambitious, TCP/IP. ... customer to have any interaface with which they can load their OWN ...
      (microsoft.public.windowsxp.embedded)