Re: Re: Penetration test report - your comments please?



This is sad state of management.Kind of like a restaurant knowing when
the health inspectors are coming.Sad,but it happens.This is when the
tester *must* shine!!!~

Regards,
Scott

Steve Chapin wrote:
What approach do most people here take? Generally, because the
client will depend on you to organize the testing, the choice is
*usually* yours. What do you think is the best method?


We always ask that our activities be known by the minimum number of
people (usually the CEO and Chief Security Officer of the client).
If the front-line people know that there is a test underway, they
will behave differently.

sc
--
== Steve J. Chapin, President ==
== RedTeam Consulting Company, LLC ==
== chapin@xxxxxxxxxxx ==




------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • RE: Volunteer pen testing
    ... You will find a sample agreement between a tester and a client. ... The scope of the pen-test is Dependant on the ... staff and co-ordinate off times for testing and contact numbers. ...
    (Pen-Test)
  • RE: IIS Kerberos auth for non-domain client
    ... > A unix kdc for realm: ... > A client pc, TESTER, running winxp sp2. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Pen Test vs. Health Check
    ... Doing both of these actually in my mind highlights the various dangers to the client. ... Rigel Kent Security & Advisory Services Inc ... hacking not solving the underlying issue of an insecure network. ... course will make a security tester. ...
    (Pen-Test)
  • White box tester Job in San Francisco, CA
    ... We have a 3 months contract-to-hire ... position with our client in San Francisco, ... We are looking for a white box tester with a strong testing/QA ...
    (comp.software.testing)