Re: Some help on methodologies and reports



Nikolaj,

If you are running windows you can try the OWASP Report Generator.

http://www.owasp.org/index.php/ORG_%28Owasp_Report_Generator%29

Thanks,
Mike de Libero
-------------- Original message ----------------------
From: Nikolaj <lorddoskias@xxxxxxxxx>
I would like to ask a few question concerning some aspects of
penetration testing.

A friend setup a little lan to mimic an ISP. He has different services -
ranging from mysql to nagios etc. I was able to penetrate one of the
server which let me to another and so forth. Eg. I penetrated his
network. Now I want to create a legit report, so that it looks like a
real one. Can you give me links or some hints on what should one such
report include? Maybe there are drafts somewhere.

I feel that what I did was more plain hacking than just pen testing.
What are the differences between them, except the business relationship.

Regards.



Relevant Pages

  • RE: Some help on methodologies and reports
    ... permission and the report. ... Then you might want a section on vulnerabilities ... penetration testing. ...
    (Pen-Test)
  • Re: Some help on methodologies and reports
    ... Submit and kick for new stories from all around the world. ... If you are running windows you can try the OWASP Report Generator. ... > penetration testing. ...
    (Pen-Test)
  • Re: External Pen Test / Manual Exploitation
    ... Instead of Penetration Testing, nomatter how ... I am in the process of reviewing a proposal for external penetration ... open source tools. ...
    (Security-Basics)
  • RE: Limited vs full blown testing
    ... First of all, most people seem to confuse auditing, vulnerability ... Penetration testing is the act of penetrating a system. ... actually penetrate is made IT ISN'T A PEN TEST! ...
    (Pen-Test)
  • Penetration Testing Report - Sample Report
    ... Imperva's Application Defense Center ... This paper demonstrates a real Application Penetration Testing Report, ... Some of the vulnerabilities presented in this paper: ...
    (SecProg)