<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <atom:link href="http://seclists.org/rss/pen-test.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
    <pubDate>Tue, 09 Mar 2010 11:00:06 GMT</pubDate>
    <lastBuildDate>Tue, 09 Mar 2010 11:00:06 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Case studies books</title>
    <link>http://seclists.org/pen-test/2010/Mar/45</link>
    <description>&lt;p&gt;Posted by David Glosser on Mar 09&lt;/p&gt;not a book, no idea how real, but  fun to watch&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://en.wikipedia.org/wiki/Tiger_Team_&quot;&gt;http://en.wikipedia.org/wiki/Tiger_Team_&lt;/a&gt;(TV_series)&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT &lt;br&gt;
and CEPT certs require a full practical examination in order to become...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 10:58:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/45</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/44</link>
    <description>&lt;p&gt;Posted by Shohn Trojacek on Mar 09&lt;/p&gt;Tony,&lt;br&gt;
&lt;br&gt;
I'd say that similar to a job interview, you could ask them to tell&lt;br&gt;
&amp;quot;war stories&amp;quot; and then measure their hesitation and response time to&lt;br&gt;
detect BS. Of course, you don't want to mistake contemplation for&lt;br&gt;
hesitation, but this is generally an effective tool in any area. For&lt;br&gt;
example, you can call up a former employer and ask if they would hire&lt;br&gt;
that person again. The lack of a response can be more telling than an&lt;br&gt;
actual response at...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 09:45:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/44</guid>
  </item>
  <item>
    <title>Re: Professional Scrpt Kiddies vs Real Talent</title>
    <link>http://seclists.org/pen-test/2010/Mar/43</link>
    <description>&lt;p&gt;Posted by Omar Herrera on Mar 09&lt;/p&gt;Hi Adriel,&lt;br&gt;
&lt;br&gt;
I agree that you have script kiddies on both ends, but  this is the &lt;br&gt;
nature of humans. You get you car these days to the mechanic and most of &lt;br&gt;
them run some kind of scanner without understanding the inner details, &lt;br&gt;
look at the report, replace the parts and that's it. They do what they &lt;br&gt;
were trained for, nothing more or nothing else, and sometimes, that's &lt;br&gt;
just what it's needed.&lt;br&gt;
&lt;br&gt;
We got scientists and experts that claim to know the...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 09:34:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/43</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/42</link>
    <description>&lt;p&gt;Posted by Jason Ross on Mar 09&lt;/p&gt;In theory, there is; see &lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityscoreboard.com&quot;&gt;http://securityscoreboard.com&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
In practice, there's a lot of security companies listed on the site&lt;br&gt;
which have little information about them posted. That's largely&lt;br&gt;
due to the fact that the site is really just starting to gain momentum,&lt;br&gt;
but it still means that not a lot of data is available.&lt;br&gt;
&lt;br&gt;
Still, even without the full realisation of user scores and such, it's&lt;br&gt;
a helpful resource IMO. Specifically, it provides a very nice...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 09:21:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/42</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/41</link>
    <description>&lt;p&gt;Posted by aceinyaface on Mar 09&lt;/p&gt;Hey Tony,&lt;br&gt;
&lt;br&gt;
This is a bit dated, but I guess this is what this guy was trying to do:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://secreview.blogspot.com/&quot;&gt;http://secreview.blogspot.com/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
I've heard a lot about Netragard and heard they provide the services  &lt;br&gt;
you are looking for and do a very good job. FWIW.&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to peers and potential employers without a doubt that...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 09:09:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/41</guid>
  </item>
  <item>
    <title>Re: Professional Scrpt Kiddies vs Real Talent</title>
    <link>http://seclists.org/pen-test/2010/Mar/40</link>
    <description>&lt;p&gt;Posted by Vikram Dhillon on Mar 09&lt;/p&gt;Thanks for that awesome email, I suppose you are right that in most cases the script kiddies are just being an &lt;br&gt;
annoyance, imagine though if they did know and fully understood what those tools did. Wouldn't that be scarier :) Then &lt;br&gt;
again, that's just my opinion, but I do strongly believe that ignorance is benifiting us one way or the other. With the &lt;br&gt;
advent of linux however, things have changed a lot, the code is open so its harder to make it...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 08:54:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/40</guid>
  </item>
  <item>
    <title>Re: Professional Scrpt Kiddies vs Real Talent</title>
    <link>http://seclists.org/pen-test/2010/Mar/39</link>
    <description>&lt;p&gt;Posted by Adriel T. Desautels on Mar 09&lt;/p&gt;Comments embedded below:&lt;br&gt;
&lt;br&gt;
When shouldn't a penetration tester be a hacker?&lt;br&gt;
&lt;br&gt;
Hence why I made the correction to our blog: &amp;quot; As far as I am concerned, these are some of the best guys in the &lt;br&gt;
industry:&amp;quot;  When I first wrote it I wrote it as if the list was all inclusive, and that's just impossible. My mistake. &lt;br&gt;
&lt;br&gt;
Care to elaborate? I might be having an idiot moment here, but I'm not following what you are trying to communicate. &lt;br&gt;
&lt;br&gt;
What does...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 08:38:27 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/39</guid>
  </item>
  <item>
    <title>Re: Professional Scrpt Kiddies vs Real Talent</title>
    <link>http://seclists.org/pen-test/2010/Mar/38</link>
    <description>&lt;p&gt;Posted by Adriel T. Desautels on Mar 09&lt;/p&gt;Hi Wim, my comments are embedded below.&lt;br&gt;
&lt;br&gt;
Why are you making the assumption that Vulnerability Research is limited to &amp;quot;products&amp;quot;? &lt;br&gt;
&lt;br&gt;
Interesting perspective and I can't say that I share your view in its entirety.  That said, I certainly agree that &lt;br&gt;
contributing to the community is of huge value.  I think that our contributions are proof of that aren't they?&lt;br&gt;
&lt;br&gt;
I love HD, so do the people on our team, but I'm not sure that I'd go so far as...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 08:08:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/38</guid>
  </item>
  <item>
    <title>Re: proposed pen-test</title>
    <link>http://seclists.org/pen-test/2010/Mar/37</link>
    <description>&lt;p&gt;Posted by Shohn Trojacek on Mar 08&lt;/p&gt;I haven't thought this very far through, but wanted to comment that&lt;br&gt;
this is hilarious for many reasons. I can imagine the look of surprise&lt;br&gt;
on the user's face.&lt;br&gt;
&lt;br&gt;
I'm not sure there would be a whole lot of value in performing this&lt;br&gt;
unless your users have been trained quite well in this area. I'm&lt;br&gt;
operating under the presumption that this is a &amp;quot;normal&amp;quot; user&lt;br&gt;
population not used to security protocols and such. In other words,&lt;br&gt;
I'd probably spend...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 07:39:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/37</guid>
  </item>
  <item>
    <title>Re: Professional Scrpt Kiddies vs Real Talent</title>
    <link>http://seclists.org/pen-test/2010/Mar/36</link>
    <description>&lt;p&gt;Posted by Wim Remes on Mar 08&lt;/p&gt;while I understand what triggered this post and/or e-mail, it is barely scratching the surface.  Infosec is so much &lt;br&gt;
more than finding vulnerabilities in products that you can hardly&lt;br&gt;
limit a list of &amp;quot;security experts&amp;quot; to people doing vulnerability research.  It just ain't right.  For me there's two &lt;br&gt;
kind of people in infosec : People that are actually contributing to a&lt;br&gt;
very open and interactive community (no, not by stepping in the...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 07:12:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/36</guid>
  </item>
  <item>
    <title>Re: proposed pen-test</title>
    <link>http://seclists.org/pen-test/2010/Mar/35</link>
    <description>&lt;p&gt;Posted by Terry Cutler on Mar 08&lt;/p&gt;Hey John, I'm actually reproducing the Hack that was done on Google&lt;br&gt;
called &amp;quot;Project Aurora&amp;quot; in a Keynot demo at Novell Brainshare. I'll be&lt;br&gt;
using Core Impact 10 to do this. In essence what happens is that Core&lt;br&gt;
installs a webserver instance on my PC and fires off an email to whom&lt;br&gt;
ever you specify and FROM who ever you want. Now, core has some built&lt;br&gt;
in HTML messages that look like the real deal such as Facebook and&lt;br&gt;
Linkedin invitations....&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 07:05:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/35</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/34</link>
    <description>&lt;p&gt;Posted by Andre Gironda on Mar 08&lt;/p&gt;Is there some kind of capital planning, budgeting, or decision-making&lt;br&gt;
process that occurs before a company seeks out to hire penetration&lt;br&gt;
testing firm(s)?&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.penetration-testing.com&quot;&gt;http://www.penetration-testing.com&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Why PCI DSS focused and not anything else? I would have rather you&lt;br&gt;
said ISO 27002, BITS FISAP, or Unified Compliance. Actually I would&lt;br&gt;
rather have you say that this is risk management and fraud management&lt;br&gt;
focused, perhaps citing standards in those areas.&lt;br&gt;
&lt;br&gt;
Ok....&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 07:00:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/34</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/33</link>
    <description>&lt;p&gt;Posted by David Glosser on Mar 08&lt;/p&gt;I would assume that a PCI  Approved Scanning Vendor (ASV) would also&lt;br&gt;
have those resources.&lt;br&gt;
Another option may to visit the PCI forums and mailing lists and check&lt;br&gt;
out the replies to user questions.  Many of those answers are from&lt;br&gt;
people who have performed PCI gap analyses and PCI audits&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 06:35:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/33</guid>
  </item>
  <item>
    <title>Re: proposed pen-test</title>
    <link>http://seclists.org/pen-test/2010/Mar/32</link>
    <description>&lt;p&gt;Posted by krymson on Mar 08&lt;/p&gt;If you have access to the mailboxes of the department, could you just slip them in with some prepared wear-and-tear on &lt;br&gt;
the packages and maybe a stamp making it look like it has been processed? Of course, now you're just pretending to be &lt;br&gt;
the real post instead of actually using them!&lt;br&gt;
&lt;br&gt;
One problem with USB keys and social testing would be any effects if your targets take the devices home to check them &lt;br&gt;
out, or give them to a student or friend or...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 06:29:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/32</guid>
  </item>
  <item>
    <title>Re: Evaluating pentesters</title>
    <link>http://seclists.org/pen-test/2010/Mar/31</link>
    <description>&lt;p&gt;Posted by Tracy Reed on Mar 08&lt;/p&gt;On Fri, Mar 05, 2010 at 07:01:33PM -0500, Tony Turner spake thusly:&lt;br&gt;
&lt;br&gt;
Just out of curiosity, what makes for a bad pen-testing firm?&lt;br&gt;
&lt;br&gt;
I'm going to be looking for one myself (PCI as well) and would like to&lt;br&gt;
know what to avoid.&lt;br&gt;
&lt;br&gt;
Although pen-testing is way-overrated IMHO. The attackers will have&lt;br&gt;
far more time and be far more resourceful than your pen-testers will&lt;br&gt;
ever be.&lt;br&gt;
&lt;br&gt;
There seems to be a cottage industry of small shops praying on&lt;br&gt;
merchants who...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 06:23:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Mar/31</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
