RE: An idiot question

From: Omar Prunera Dols (oprunera_at_salleURL.edu)
Date: 10/28/04

  • Next message: Andre Ludwig: "Re: VoIP pentest ?"
    Date: Thu, 28 Oct 2004 17:13:08 +0200 (CEST)
    To: pen-test@securityfocus.com
    
    

    Hi all,

    I totally agree with Todd with his definition of pen-testing (Pen-test is
    like controlled hacking...), but when he says that there's no "exactly how
    to do it manual", i would say that's not 100% correct. Have your ever
    heard about OSSTMM?. This is the Open Source Security Testing Methodology
    Manual, and is not a "how to do manual" but is a good guideline to perform
    correctly a security test.

    I recommend you to take a look at http://isecom.org and to the OSSTMM

    See you

    On Tue, 26 Oct 2004, Todd Towles wrote:

    > Run over to insecure.org and look at all the tools. Pen-test is like
    > controlled hacking...there is no "exactly how to do it manual" and to
    > tell you the truth, there really shouldn't be one.
    >
    > Read, read read....and then..do do do in a controlled world. Reading
    > everything in sight can get you to the door with the information but
    > only "doing" can step you into the other room.
    >
    > > -----Original Message-----
    > > From: Profeta [mailto:profetago@bol.com.br]
    > > Sent: Tuesday, October 26, 2004 10:31 AM
    > > To: pen-test@securityfocus.com
    > > Subject: An idiot question
    > >
    > > Is there some sites that given an arsenal of tools to realize
    > > pen tests ? I know that www.packetstormsecurity.nl is a good
    > > start, but, there is another site that is more expecific to
    > > download some tools ? Thanks the attention!
    > >
    > > Pr0ph3t
    > >
    > > --------------------------------------------------------------
    > > ----------------
    > > Internet Security Systems. - Keeping You Ahead of the Threat
    > >
    > > When business losses are measured in seconds, Internet
    > > threats must be stopped before they impact your network. To
    > > learn how Internet Security Systems keeps organizations ahead
    > > of the threat with preemptive intrusion prevention, download
    > > the new whitepaper, Defining the Rules of Preemptive
    > > Protection, and end your reliance on reactive security technology.
    > >
    > > http://www.securityfocus.com/sponsor/ISS_pen-test_041001
    > > --------------------------------------------------------------
    > > -----------------
    > >
    > >
    >
    > ------------------------------------------------------------------------------
    > Internet Security Systems. - Keeping You Ahead of the Threat
    >
    > When business losses are measured in seconds, Internet threats must be stopped before they impact your network. To learn how Internet Security Systems keeps organizations ahead of the threat with preemptive intrusion prevention, download the new whitepaper, Defining the Rules of Preemptive Protection, and end your reliance on reactive security technology.
    >
    > http://www.securityfocus.com/sponsor/ISS_pen-test_041001
    > -------------------------------------------------------------------------------
    >
    >

    Sincerely,
    -omar.

    Omar Prunera i Dols

    Networking Dept. - Security Area
    Enginyeria i Arquitectura La Salle

    Homepage: http://omar.squarespace.com
    E-mail: oprunera@salleurl.edu
            omar@isecom.org
            omar@ideahamster.org
            oprunera@gmail.com


  • Next message: Andre Ludwig: "Re: VoIP pentest ?"

    Relevant Pages

    • Re: Zaurus audit tools
      ... IT Technical Security Officer ... Internet Security Systems. ... To learn how Internet Security ... Systems keeps organizations ahead of the threat with preemptive ...
      (Pen-Test)
    • MI5 Boss hints kiss goodbye to civil rights...
      ... "THE INTERNATIONAL TERRORIST THREAT AND THE DILEMMAS IN COUNTERING IT" ... I am delighted to be here to celebrate the 60th Birthday of the AIVD. ... The friendship between the AIVD and my Service, the British Security ... fascism then, by the time I met him, on countering terrorism. ...
      (soc.culture.scottish)
    • RE: What is being a pen tester really like?
      ... security assessment and penetration ... pen-testing isn't exactly rocket science. ... What is being a pen tester really like? ... Download FREE whitepaper on how a managed service can help ...
      (Pen-Test)
    • Re: NDC-Al Gore invented being a hypocrite
      ... misuse terror threats to manipulate the public for political purposes. ... It said nothing about this particular instance, and it no way implies ... or suggests that this specific threat or the threat of terrorism in ... time of war or national unrest due to security issues. ...
      (rec.music.gdead)
    • Re: U.S. Embassy Warning Of Possible Terror Attack On 4-5 Star Hotels in China
      ... November 9 Threat Message Retracted ... The Chinese Ministry of Public Security informed the U.S. Embassy in Beijing ...
      (rec.travel.asia)