Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




pen-test logo Penetration Testing mailing list archives

Re: nessus exceptions
From: Stefano Zanero <stefano.zanero () ieee org>
Date: Tue, 10 Aug 2004 18:46:38 +0200

FocusHacks wrote:

Indeed, most pen-testers will disclose what tools they use and the raw
output of these tools if you ask.  Especially if you let them know
before the testing starts, that you'll want this information.

It would be sad if your assessment team is doing little more than
cleaning up and adding documentation to a nessus scan report.  :(

It seems to me that we are mixing up again two VERY different things: vulnerability assessment and pen-testing.

If a pen-testing company just uses nessus it shouldn't be difficult to spot, because nessus is NOT going to give out a pen-test report, in no way :)

So we have to assume that we are talking about VULNERABILITY ASSESSMENT companies... and the question actually is, how many of the "commercial vulnerability scanners" out there are not actually based on Nessus ? :)

Stefano


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]