RE: Limited vs full blown testing

From: Jerry Shenk (jshenk_at_decommunications.com)
Date: 06/25/04

  • Next message: Max: "Auditor security collection announcement"
    To: "'R. DuFresne'" <dufresne@sysinfo.com>
    Date: Thu, 24 Jun 2004 18:37:15 -0400
    
    

    He SPECIFICALLY excluded DDOS. Of course, if you sit in on the network
    with a battery of laptops and find a few amplifiers internally, you can
    do a DDOS...that's why he excluded it. In fact, it was the VERY NEXT
    sentence after the first sentence you snipped out. How about some more
    basic DOS attempts. Doing that type of thing internally doesn't seem
    very practical to me.

    Now, about doing a DOS in a penetration test or vulnerability
    assessment...sure, it makes sense.

    -----Original Message-----
    From: R. DuFresne [mailto:dufresne@sysinfo.com]
    Sent: Thursday, June 24, 2004 4:13 PM
    To: Peter Wood
    Cc: pen-test@securityfocus.com
    Subject: Re: Limited vs full blown testing

            [SNIP]

    >
    > We accept a brief excluding DoS attacks, as most clients just won't
    support
    > DoS testing. However we include appripriate caveats in our report and
    > continue to suggest they do these tests.
    >

    I'm trying to understand the significance of DDOS testing and
    importance.
    Thing is, if you can spew packets fast enough, or make enough
    connections
    to consume the resources involved, you can take a site/serice down for
    at
    least the duration of the attack, even pipes as large as those of
    akami<sp?> were proven to be susceptable in recent days. It's a given
    vector of attack that we live with, a risk level we hope to avoid. But,
    not something that gives away the insides of the network to thugs and
    theives. No root shell and all that, which constitute a real threat, at
    least in my mind. Perhaps I'm missing something that has come up in
    recent years that redefines DDOS as something that is preventable and a
    potential for something other then a blip, however long lasting the
    attack, in service?

    Thanks,

    Ron DuFresne

    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    testing, only testing, and damn good at it too!
    

  • Next message: Max: "Auditor security collection announcement"

    Relevant Pages

    • RE: Limited vs full blown testing
      ... >I'm trying to understand the significance of DDOS testing and importance. ... >vector of attack that we live with, a risk level we hope to avoid. ... Ron - I think the difference here is DoS vs. DDoS. ... throwing packets at a target to fill all available bandwidth and I can't see ...
      (Pen-Test)
    • RE: Limited vs full blown testing
      ... > been some exploits that require a two fold attack. ... In other words, the DOS ... Understood, one of the basic reasons that security is a layered approcah, ... > I'm trying to understand the significance of DDOS testing and importance. ...
      (Pen-Test)
    • Re: IPspoofing
      ... The short answer is that, especially if the threat is DDoS, you can't. ... to disguise the true source of the attack. ... > Este mensaje puede contener información confidencial y/o privilegiada. ... Internet communications are not secure and therefore the Barclays ...
      (Security-Basics)
    • RE: any recommendable anti-ddos solution?
      ... With DDOS you cannot simply block a host, DDOS is originating from lots of ... different subnets on different geographic locations, so blocking a host ... attack, for example if I know you have an IPS system that denies traffic ... and the switch that goes to everything else inside the network. ...
      (Security-Basics)
    • RE: Client DDoS requests, ideas?
      ... The DDOS protection company you are thinking about is www.prolexic.com ... take into consideration that a real DDOS attack will not only take down the ... Asunto: Re: Client DDoS requests, ...
      (Pen-Test)