Home page logo

pen-test logo Penetration Testing mailing list archives

Vulnerability Assessment of a EAL 4 system
From: <castellan2004-fd () yahoo com>
Date: Wed, 1 Nov 2006 02:11:38 -0800 (PST)

I am looking at a Linux server which has been
accredited as a EAL4 system by IBM.  During the
assessment, I was looking for standard Linux
protections like iptables, ssh etc.  On this server,
there is no iptables.

Regardless, I would like to know how to evaluate a EAL
4 system.  What do you need to look for in the EAL 4
system in production that could become vulnerable?

Thank you in advance for any help.

This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]