RE: pen test



Michael,

Am I wrong, but there are lots of practices and in some cases laws that
say that you need to run vulnerability assessments to be compliant.
If you were to ask you web host in writing before doing it, that should
solve the possible "legality" issue that it sounds like you talking
about.

As far as I know, White Hat hacking has never been illegal, if done
correctly and above board. If it was, why would SANS and other offer
Certified Hacker classes and certs?

Thanks
Brian

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Michael R. Martinez
Sent: Monday, December 10, 2007 7:54 PM
To: Marty Resnick; listbounce@xxxxxxxxxxxxxxxxx; security-basics
Subject: Re: pen test

Marty,

absolutely not, this is called hacking. Pen testing is actively
exploiting a server, identifying a weakness exploiting gaining access.
Are you talking about scanning ports? Could you provide a little more
detail. If you mean pen-testing, then the answer is no.

Cheers
------Original Message------
From: Marty Resnick
Sender: listbounce@xxxxxxxxxxxxxxxxx
To: security-basics
Sent: Dec 10, 2007 9:35 AM
Subject: pen test

Am I able to pen test or run a vulnerability assessment on my web
hosting company. I got the idea after reading this article.
http://www.securitypark.co.uk/Security_article.asp?articleid=260173

--
Marty Resnick
Techmaking Inc.
(877) 291-1110 (office)
(661) 209-2089 (mobile)
(805) 512-9603 (fax)
marty@xxxxxxxxxxxxxx



Michael R. Martinez
TF: 800-987-7307



Relevant Pages

  • Re: pen test
    ... You cannot ask your host to subvert there security measures but they will certainly deny you, you can however, ask that you run security scans because there are services for this such as comodo and scan alert. ... Subject: pen test ... On Behalf Of Michael R. Martinez ...
    (Security-Basics)
  • Re: pen test
    ... Be sure to get the authorization in writing though in case your test causes problems and they try to take legal action. ... Pen testing is actively exploiting a server, identifying a weakness exploiting gaining access. ... Am I able to pen test or run a vulnerability assessment on my web hosting company. ...
    (Security-Basics)