Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: Security Audit

Re: Security Audit

From: H C <keydet89_at_yahoo.com>
Date: Wed, 12 Sep 2001 17:49:38 -0700 (PDT)

For the most part, I agree with Ben's comments. For
completeness, a system can be as secure as possible if
a vulnerability assessment of that system is
conducted, and that information is then used to launch
a "full disclosure pen-test" or perhaps more
appropriately, a "verification analysis".

However, like anything else, this is only a snapshot
of the system in time. We then get into the change
control/management process, and where verification
testing fits in such a process.

> But any "analysis" process should include external
> verification - ie that
> the box is doing what you told it to do, right?
>
> This is quite distinct from the traditional pen-test
> in that it isn't blind.
>
> I think that to create the most secure system
> possible, blind pen-testing is
> a waste of time -

__________________________________________________
Do You Yahoo!?
Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger
http://im.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/
Received on Sep 13 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]