RE: Using viruses in pen-test



Use the EICAR test files (http://www.eicar.org/). Innocuous payloads
recognized by all AV manufacturers. A "standard" test pattern, just like
real virus patterns.

Check out the web site for more info

kev

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On
Behalf Of neo anderson
Sent: Wednesday, October 11, 2006 3:08 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Using viruses in pen-test

Hi List,
I wish to know your views on "Using viruses in pen-test"I
I've been working in the infosec domain for over 2 years with a couple
of infosec certs including CEH and conducting pen-tests for my clients
for about a year.

My recent client has hired me for carrying out "every possible" type
of pen test.
This includes testing organizations defence mechanism against viruses
as well, this includes to test whether anti-virus administrators have
up-to-date virus definitions etc. I'm supposed to gather this
information by means of thorough penetration tests only.

As we all are aware that how the viruses (worms/trojans included)
enter into the corporate network propagate over LAN. There are many
ways like email attachments or infected content brought in by
employee.It spreads on itself thereafter.

Now my question:

Is there any standard procedure to test the posture of organizations
network security against potential virus threats? I mean i wish to
know about pen-test carried out against Antivirus-product. In order to
replicate itself, a virus must be permitted to execute code and/or
write to memory. Thus this pen-test should also tests that.
And do I need to use some known viruses for this kind of pen-test?

Have your thoughts on this topic please.
Thanking you all.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------




------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • RE: Using viruses in pen-test
    ... I wonder if there is some type of "fake" virus you could use in this case. ... David A. Swafford, Network Engineer ... I wish to know your views on "Using viruses in pen-test"I ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • RE: Using viruses in pen-test
    ... I think it is extremely unwise for a company to ask you check their virus policy by attempting to unleash 3rd party, known malicious code, on the network. ... I wish to know your views on "Using viruses in pen-test"I ... know about pen-test carried out against Antivirus-product. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Using viruses in pen-test
    ... I've been working in the infosec domain for over 2 years with a couple ... This includes testing organizations defence mechanism against viruses ... up-to-date virus definitions etc. I'm supposed to gather this ... Thus this pen-test should also tests that. ...
    (Pen-Test)
  • The Truth About AIDS. Biological Warfare at is finest
    ... AIDS was created in a test tube and released into the population. ... Contrary to widespread speculations that human AIDS viruses arose from ... National Cancer Institute researchers noted that "only one virus ... virus RNA, associated with leukemia and sarcoma development, and ...
    (rec.org.mensa)
  • Re: WHO: Swine Flu Could Trigger Global Pandemic
    ... all worked up over the right of humans to temporarily camp in The ... Its a natural process, viruses are able ... sense of what a virus is and how it works. ... host as it is replicating, and transfer this genetic information to a ...
    (alt.gathering.rainbow)