Re: Cross testing exploit with vulnerability scan results



On 7/29/07, Anders Thulin <anders.thulin@xxxxxxxxx> wrote:
(This is why computer penetration testing ultimately is a dead end.
Security can't rely on penetration testing for anything but reports
of bad security.)

-yup.
pentests can tell client only like "your security sucks or we are
unsure" if used for assurance on security. it can used for eyeopener
(if those still are needed). testing insicent&response processes,
monitoring function etc.
the "sucks" part is due to being able to getting in and deleting all
things from db, the "we are unsure" part is when you have all claims
that during this timeframe, with available information, exploits,
skills etc etc.

_jussi

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: Security policies are propagated with warning. 0xd : The data is invalid.
    ... I'm looking at this purely from the security policy perspective. ... Userenv.log error is also troublesome but I'm unsure why it would be ... there's a GUID in the template that identifies which GPO it came from. ...
    (microsoft.public.win2000.active_directory)
  • RE: Standards for penetration testing
    ... Computer Security Certification of Trusted Systems ... Subject: Standards for penetration testing ... All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
    (Pen-Test)
  • RE: Penetration testing scope/outline
    ... person doesn't come right out and say they are new to Security, ... Subject: Penetration testing scope/outline ... methodology is modified to that particular type of test. ... of you who don't have the manual handy, that page says INCOMPLETE ...
    (Pen-Test)
  • Re: Pen-testing Internships?
    ... If you wish to address Rob Kraus' specific interests (internship offers etc) please email him directly to reduce list clutter. ... very good resource for learning and collaboration among IT Security ... Download FREE whitepaper on how a managed service can ... Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. ...
    (Pen-Test)
  • RE: Aspiring Pen-Tester Seeking Advice
    ... HACK I.T - Security trough penetration testing. ... is probably best for application- and OS-level attacks (where a good ... buy it or download a solution FREE today! ...
    (Pen-Test)