Full Disclosure mailing list archives
Re: Verisign abusing .COM/.NET monopoly, BIND releases new
From: "Nexus" <nexus () patrol i-way co uk>
Date: Thu, 18 Sep 2003 00:57:02 +0100
----- Original Message ----- From: "Michael Scheidell" <scheidell () secnap net> [snip]
One more interesting thing, if you have a client who has given you ip addresses for external testing, and these ip addresses rdns to a domain that doens't FWD resolve, you wil end up pen testing verisign's computers.
I don't think so... or, put another way, I hope not ;-) As any fule kno, part of the <Yank>"Due Diligence"</Yank> process on receipt of IP ranges from a Client would be to conduct whois type searches to determine that the Client has indeed not typo'd an IP range or CIDR block. I've had this happen a few times and a cursory whois + confirmation has sorted the incorrect ranges before testing actually starts. Sometimes it's not even obvious from a whois which is all part of the fun of it. One hopes that the pen testers you employ also do this... :P Cheers. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: DCOM/RPC story (Analogy) ww (Aug 31)
- RE: DCOM/RPC story (Analogy) Steven Fruchter (Aug 31)
- <Possible follow-ups>
- RE: DCOM/RPC story (Analogy) Nick FitzGerald (Aug 31)
- RE: DCOM/RPC story (Analogy) madsaxon (Aug 31)
- Re: DCOM/RPC story (Analogy) Jennifer Bradley (Aug 31)
- Re: DCOM/RPC story (Analogy) Kristian Hermansen (Sep 01)
- Re: DCOM/RPC story (Analogy) Jarmo Joensuu (Sep 01)
- RE: DCOM/RPC story (Analogy) Schmehl, Paul L (Sep 01)
- Re: DCOM/RPC story (Analogy) morning_wood (Sep 01)
- Re[2]: DCOM/RPC story (Analogy) Marc Chabot (.net) (Sep 01)
- Re: DCOM/RPC story (Analogy) morning_wood (Sep 01)
