Re: Limited vs full blown testing

From: R. DuFresne (dufresne_at_sysinfo.com)
Date: 06/24/04

  • Next message: Rosado, Rafael (Rafael): "SecurityExpressions from Pedestal Software"
    Date: Thu, 24 Jun 2004 16:13:05 -0400 (EDT)
    To: Peter Wood <peterw@firstbase.co.uk>
    
    

            [SNIP]

    >
    > We accept a brief excluding DoS attacks, as most clients just won't support
    > DoS testing. However we include appripriate caveats in our report and
    > continue to suggest they do these tests.
    >

    I'm trying to understand the significance of DDOS testing and importance.
    Thing is, if you can spew packets fast enough, or make enough connections
    to consume the resources involved, you can take a site/serice down for at
    least the duration of the attack, even pipes as large as those of
    akami<sp?> were proven to be susceptable in recent days. It's a given
    vector of attack that we live with, a risk level we hope to avoid. But,
    not something that gives away the insides of the network to thugs and
    theives. No root shell and all that, which constitute a real threat, at
    least in my mind. Perhaps I'm missing something that has come up in
    recent years that redefines DDOS as something that is preventable and a
    potential for something other then a blip, however long lasting the
    attack, in service?

    Thanks,

    Ron DuFresne

    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    testing, only testing, and damn good at it too!
    

  • Next message: Rosado, Rafael (Rafael): "SecurityExpressions from Pedestal Software"

    Relevant Pages

    • OT: Re: 400 dead soldiers and marines in the month of October 2006...
      ... Insurgent mortar fire hit an American military ammunition dump late ... FOB Falcon is in the central Rasheed district of Baghdad. ... attack on Camp Liberty. ... Stars and Stripes reporter Anita Powell contributed to this report. ...
      (rec.sport.boxing)
    • (forw) "Power" bot (was Re: NEW DEVELOPMENT -- Attempts at using CodeRed II systems to per
      ... Subject: "Power" bot (was Re: NEW DEVELOPMENT -- Attempts at using CodeRed ... >> perform a denial of service attack. ... If you see evidence of this on your systems or networks, report this ... The following is a report of distributed scanning, ...
      (Incidents)
    • "Power" bot (was Re: NEW DEVELOPMENT -- Attempts at using CodeRed II systems to perform D
      ... Subject: "Power" bot ... >> perform a denial of service attack. ... If you see evidence of this on your systems or networks, report this ... The following is a report of distributed scanning, ...
      (Incidents)
    • Re: Blackice Firewall
      ... > Well a threat basically is unsolicited inbound traffic from the Internet ... > Yes read the BI User manual to find out what attempts BI will report on. ... > So the bottom line is set the BI Reporting Level to RED, ... > with BI attack indicator Icon. ...
      (comp.security.firewalls)
    • Re: FUCK THIS MOTHER FUCKING GROUP, GAWD DAMMIT
      ... > If being reported to the DEA is a false report then why the heck are you ... > so mad about it and trying so hard not to retaliate, ... >> others attack me for several weeks after, ... Cabbi is from an old Beach Boys song on the Smile album. ...
      (alt.support.chronic-pain)