Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: RE: Pen testing a off-site web server

RE: Pen testing a off-site web server

From: Jim Huddleston <hudd3_at_ix.netcom.com>
Date: Tue, 22 May 2001 18:47:58 -0500

Additionally ask if any testing is part of the SLA between the provider and
client. If not recommend that the SLA include it when the contract is
renewed. I have had some ISP's refuse testing and others who only want it
conducted on-site at their facilities. Make sure you are flexible as to the
time you run the tests. Generally they will want them run during off hours.

Regards,

Jim Huddleston, CISSP
hudd3_at_ix.netcom.com

-----Original Message-----
From: batz [mailto:batsy_at_vapour.net]
Sent: Tuesday, May 22, 2001 5:22 AM
To: Franklin DeMatto
Cc: pen-test_at_securityfocus.com
Subject: Re: Pen testing a off-site web server

On Sun, 20 May 2001, Franklin DeMatto wrote:

:Anyone know how to handle the legal/bueracratic aspects of pen-testing a
web server which is not in-house, but property of a hosting company??
:
:Any real-world advice, forms, paperwork, or legal info. would be
appreciated.

Have your client inform their vendor that they require a third party of
their
choosing to evaluate the security of their own networks and digital assets.
The vendor may give some pushback, but you can give them assurances that
no interruption of service will occur, give them a 24/7 number to reach
the testing staff at, and make sure your client states that it is a part
of their security policy to require this testing on all internal, and vendor
supplied equipment. "Requirement" meaning, "in order to do business with".

I think the vendor should be accomodating.

--
batz
Reluctant Ninja
Defective Technologies
Received on May 24 2001
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos