Re: Penetration Test/Vulnerability Study

From: Bogus Strawman (bogusstrawman_at_hotmail.com)
Date: 07/21/04


Date: Wed, 21 Jul 2004 05:31:19 GMT

We've had a couple of these done - the testers in our case initially used
normal tools like nessus (http://nessus.org) and hping
(http://wiki.hping.org). Once they did the initial scan, they would then
try out the vulnerabilities exposed. They also did alot of messing about
on the websites looking for local coding vulnerabilites.

In all they took about 2 weeks.

On Sun, 18 Jul 2004 20:51:25 -0700, Sherman H. wrote:

> I am searching for what areas are tested for a regular penetration test done
> by a consultant. We are thinking about doing that by ourselves Info
> Security Team and would like to have a comprehensive listing of the scope.
> Any links are appreciated.