Re: Cross testing exploit with vulnerability scan results



Morning Wood schrieb:
I've been conducting pen tests since 4 yrs now... the methodology I
follow is that we exploit or attempt to exploit ONLY those
vulnerabilities that a vulnerability scanner identifies.

your not a pentester... your a vulnerability scanner kiddi...
nothing more, nothing less.

Nearly 100% of my successfull pentest were
from flaws not uncovered by a vuln scan, found
by manual techniques.

cheers!
m.w

I agree fully with you....
cheers
Jan



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Cross testing exploit with vulnerability scan results
    ... vulnerabilities that a vulnerability scanner identifies. ... You need to know and trust your vulnerability scanner to do what you ... But a pen test is not about finding negatives: ... anything from a vulnerability scan (but no followup penetration attempts) ...
    (Pen-Test)
  • Re: The Best Network Scanner?
    ... I would give Nessus a try, it works on linux, its easy to install and use, ... its a good vulnerability scanner, and best of all it is free. ... > network scanners on the market for finding vulnerabilities on your network, ...
    (Security-Basics)
  • Re: Cross testing exploit with vulnerability scan results
    ... vulnerabilities that a vulnerability scanner identifies. ... Nearly 100% of my successfull pentest were ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: Fwd: Terminal services and remote programs.
    ... Our team regularly breaks into Terminal Servers ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities ...
    (Pen-Test)
  • RE: Fwd: Terminal services and remote programs.
    ... "help/about vulnerabilities" that were mentioned here a few days ago. ... TerminalServices and RemoteApp deployments, including ... Need to secure your web apps NOW? ...
    (Pen-Test)