RE: Pen Test of a ESX Server



You could begin with the review procedures in the corresponding
checklist, (though you may have already thought of that since you are
testing against the STIG).

http://iase.disa.mil/stigs/checklist/vmchklst-v2r12-APR06.doc

Good luck,
Jim

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of jfvanmeter@xxxxxxxxxxx
Sent: Wednesday, August 15, 2007 10:01 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Pen Test of a ESX Server


I have a assignment to complete a pen test of a ESX server and was
hoping to get some thoughts from everyone on how and what to test. I
need to check to see if the server is configured in accordance with the
"Virtual Computing Security Technical Implementation Guide" Version 1,
release0.1

Thank You in advance

Take Care and Have Fun --John

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: How to report a Vulnerability to a Company
    ... in my eyes, unless you make it a habit of yours to pen test systems you weren't paid for, you shouldn't even try and hack them if you decide do something illegal I would expect that it is all a matter of time and money, how much for how long that company is willing to pay in order to find out who infiltrated their systems. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: Pen Test and Sec Org
    ... Pen Test and Sec Org ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)