RE: An idiot question

From: Richard Zaluski (rzaluski_at_ivolution.ca)
Date: 11/02/04

  • Next message: Ivo Batchvarov: "Re: VoIP pentest ?"
    To: "'Omar Prunera Dols'" <oprunera@salleURL.edu>, <pen-test@securityfocus.com>
    Date: Tue, 2 Nov 2004 09:00:31 -0500
    
    
    

    I agree with Omar, the OSSTMM is a great resource and also allows a
    'certified' pen test if sections are followed.

    The OSSTMM is part of iVolutions Applied Penetration Testing Course Material
    and is used throughout the course to show students methodology behind a
    Professional Security / Penetration Test. A Pen Test is NOT simply finding
    the target and running tools. Tools and methodology go hand in hand. You
    NEED a methodology and you NEED to understand how, when, where and what to
    run in the way of tool sets to achieve the Methodologies expected results.

    For those who do not understand the concepts of Penetration testing the
    OSSTMM is a 'guideline' for Penetration testing and is recognized in the
    industry.

    Our advice :
    Setup a test network
    Test tools.
    Read all you can get your hands on about not just Pen Testing but Security
    Testing
    A lot of your time will be in Research in the Security Testing Vulnerability
    arena.
    Apply those tools to achieve the expected results in the OSSTMM Sections
    Sign up with online message boards that send you updates on exploits and
    vulnerabilities.
    Take a course if you can.

    Also some organizations have mentor / student programs in which gives you
    access to someone you can bounce questions off and be a resource.

    Just our 2 cents!

    Richard Zaluski, CCNA, CRCP
    CISO, Security and Infrastructure Services
    iVolution Technologies Incoporated
    905.309.1911
    866.601.4678
    905.524.8450 (Pager)
    www.ivolution.ca
    rzaluski@ivolution.ca
     

    =======================================================================
    === CONFIDENTIALITY NOTICE: This email message, including any
    attachments, is for the sole use of the intended recipient(s) and may
    contain confidential and privileged information. If you are not the
    intended recipient, please contact the sender. Any unauthorized review,
    use, disclosure, or distribution is prohibited.
    =======================================================================
    ===
     
    PGP Key-ID: 85544DB6
    PGP Key fingerprint: 0CD3 FB61 EAF1 11CA 8EC4 513A 75F2 6FC0 8554
    -----Original Message-----
    From: Omar Prunera Dols [mailto:oprunera@salleURL.edu]
    Sent: Thursday, October 28, 2004 11:13 AM
    To: pen-test@securityfocus.com
    Subject: RE: An idiot question

    Hi all,

    I totally agree with Todd with his definition of pen-testing (Pen-test is
    like controlled hacking...), but when he says that there's no "exactly how
    to do it manual", i would say that's not 100% correct. Have your ever
    heard about OSSTMM?. This is the Open Source Security Testing Methodology
    Manual, and is not a "how to do manual" but is a good guideline to perform
    correctly a security test.

    I recommend you to take a look at http://isecom.org and to the OSSTMM

    See you

    On Tue, 26 Oct 2004, Todd Towles wrote:

    > Run over to insecure.org and look at all the tools. Pen-test is like
    > controlled hacking...there is no "exactly how to do it manual" and to
    > tell you the truth, there really shouldn't be one.
    >
    > Read, read read....and then..do do do in a controlled world. Reading
    > everything in sight can get you to the door with the information but
    > only "doing" can step you into the other room.
    >
    > > -----Original Message-----
    > > From: Profeta [mailto:profetago@bol.com.br]
    > > Sent: Tuesday, October 26, 2004 10:31 AM
    > > To: pen-test@securityfocus.com
    > > Subject: An idiot question
    > >
    > > Is there some sites that given an arsenal of tools to realize
    > > pen tests ? I know that www.packetstormsecurity.nl is a good
    > > start, but, there is another site that is more expecific to
    > > download some tools ? Thanks the attention!
    > >
    > > Pr0ph3t
    > >
    > > --------------------------------------------------------------
    > > ----------------
    > > Internet Security Systems. - Keeping You Ahead of the Threat
    > >
    > > When business losses are measured in seconds, Internet
    > > threats must be stopped before they impact your network. To
    > > learn how Internet Security Systems keeps organizations ahead
    > > of the threat with preemptive intrusion prevention, download
    > > the new whitepaper, Defining the Rules of Preemptive
    > > Protection, and end your reliance on reactive security technology.
    > >
    > > http://www.securityfocus.com/sponsor/ISS_pen-test_041001
    > > --------------------------------------------------------------
    > > -----------------
    > >
    > >
    >
    >
    ----------------------------------------------------------------------------

    --
    > Internet Security Systems. - Keeping You Ahead of the Threat
    >
    > When business losses are measured in seconds, Internet threats must be
    stopped before they impact your network. To learn how Internet Security
    Systems keeps organizations ahead of the threat with preemptive intrusion
    prevention, download the new whitepaper, Defining the Rules of Preemptive
    Protection, and end your reliance on reactive security technology.
    >
    > http://www.securityfocus.com/sponsor/ISS_pen-test_041001
    >
    ----------------------------------------------------------------------------
    ---
    >
    >
    Sincerely,
    -omar.
    Omar Prunera i Dols
    Networking Dept. - Security Area
    Enginyeria i Arquitectura La Salle
    Homepage: http://omar.squarespace.com
    E-mail: oprunera@salleurl.edu
    	omar@isecom.org
    	omar@ideahamster.org
    	oprunera@gmail.com
    


  • Next message: Ivo Batchvarov: "Re: VoIP pentest ?"

    Relevant Pages

    • Re: RE: OSSTMM how good is it?
      ... that if thorough testing is needed, OSSTMM works best for us. ... excellent framework for security testing. ... Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. ...
      (Pen-Test)
    • Re: Verify Your Security Provider -- The truth behind manual testing.
      ... manual testing, not just automated scans. ... greater than the cost of the best possible security services. ... should be) asking for and b) to evaluate the proposals from vendors. ... If you want to be protected from the threat, you need to be tested at ...
      (Pen-Test)
    • MI5 Boss hints kiss goodbye to civil rights...
      ... "THE INTERNATIONAL TERRORIST THREAT AND THE DILEMMAS IN COUNTERING IT" ... I am delighted to be here to celebrate the 60th Birthday of the AIVD. ... The friendship between the AIVD and my Service, the British Security ... fascism then, by the time I met him, on countering terrorism. ...
      (soc.culture.scottish)
    • RE: OPST and CEH
      ... I took Feb. 2-6, 2004, the OPST Certification course offered in Ft. ... In addition to the OSSTMM methodology ... with LOTS of material on Ethical Hacking techniques. ... covers the period BEFORE, DURING, and AFTER the security testing is ...
      (Pen-Test)
    • RE: Standards for penetration testing
      ... Computer Security Certification of Trusted Systems ... Subject: Standards for penetration testing ... All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
      (Pen-Test)