Re: Why Penetration Test?

From: Marco Ivaldi (raptor_at_0xdeadbeef.info)
Date: 06/29/05

  • Next message: Thomas Brennan: "RE: CEH training"
    Date: Wed, 29 Jun 2005 18:34:05 +0200 (CEST)
    To: pen-test@securityfocus.com
    
    

    > I was wondering the usefulness of a penetration testing against
    > vulnerability assessment for a company.

    Hey pen-testers,

    First of all, i apologize for coming so late to the party -- i've been far
    from the Internet for a couple of weeks lately...

    Just wanted to point out something crucial to me that surprisingly enough
    has not been mentioned yet in this discussion: a security professional
    must always remember that there are some attack vectors that are hard (if
    not impossible) to spot and test thoroughly using automated VA tools.

    Yeah, not all attacks come from the IP infrastructure: instead, in my
    personal and professional experience i witnessed that most dangerous
    attacks come very often through PBX, RAS connected to a PSTN, backup ISDN
    lines connected to routers, good old X.25 networks, etc. Also, not all
    attacks can be easily reproduced using automated VA tools: just think
    about common technologies as WLANs and (web) applications in general, an
    automated testing approach would definitely miss some attack paths. Not to
    mention social engineering, physical intrusions, dumpster diving, and
    other popular ways to fool your expensive security measures.

    In short, my point is: depending on the complexity of my operational
    environment, i'd be very careful before deciding to rely _only_ on the
    common IP infrastructure vulnerability assessments done with popular
    automated scanning tools to secure my information. There's more outta here
    that must be tested to ensure you get a 360 degrees vision of your
    organization's security posture and IMHO a good consultant should tell you
    before selling you yet another superficial VA.

    Just my 2 euro-cents;) Cheers,

    -- 
    Marco Ivaldi
    Antifork Research, Inc.   http://0xdeadbeef.info/
    3B05 C9C5 A2DE C3D7 4233  0394 EF85 2008 DBFD B707
    

  • Next message: Thomas Brennan: "RE: CEH training"

    Relevant Pages

    • RE: Aspiring Pen-Tester Seeking Advice
      ... HACK I.T - Security trough penetration testing. ... is probably best for application- and OS-level attacks (where a good ... buy it or download a solution FREE today! ...
      (Pen-Test)
    • Re: Free Penetration Testing Workshop in Bristol, UK
      ... > This three-hour Penetration Testing workshop will introduce attendees to ... > penetration testing can make a huge difference in your security program. ... > Attendees will see live or simulated demonstrations of attacks on computer ...
      (microsoft.public.cert.exam.mcse)
    • Free Penetration Testing Workshop in Bristol, UK
      ... This three-hour Penetration Testing workshop will introduce attendees to ... penetration testing can make a huge difference in your security program. ... Attendees will see live or simulated demonstrations of attacks on computer ...
      (microsoft.public.cert.exam.mcse)
    • Penetration Testing/Vulnerability Assessment
      ... Subject: Penetration Testing/Vulnerability Assessment ... I have been reading about the reponses on "Security Audit" and I have learnt ... Would one do a vulnerability assessment first and then penetration testing? ...
      (Pen-Test)
    • [Full-Disclosure] Presentation / Paper : Demystifying Penetration Testing
      ... mostly targeted for those who are new to Penetration Testing (i.e. ... Security Officers / Sys Admins / Security Auditors / Security ... This presentation will give a clear picture on how pen ... - An overview of how Vulnerability Assessment & Penetration Testing ...
      (Full-Disclosure)