|
Penetration Testing
username and Password sent as clear text strings May 14 2008 10:39AM jfvanmeter comcast net (6 replies) Re: username and Password sent as clear text strings May 20 2008 12:06AM Matthew Zimmerman (mzimmerman gmail com) (1 replies) Re: username and Password sent as clear text strings May 20 2008 08:43AM David Howe (DaveHowe Pentest googlemail com) (1 replies) Re: username and Password sent as clear text strings May 21 2008 06:40PM Matthew Zimmerman (mzimmerman gmail com) (1 replies) Re: username and Password sent as clear text strings May 23 2008 09:39AM David Howe (DaveHowe Pentest googlemail com) Re: username and Password sent as clear text strings May 15 2008 02:35PM Orlin Gueorguiev (orlin baturov com) RE: username and Password sent as clear text strings May 15 2008 02:29PM Jones, David H (Jones David H principal com) (1 replies) Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 16 2008 02:46AM Brahnda A. Eleazar (brahnda e hermisconsulting com) (4 replies) Re: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 17 2008 07:49AM Rick Zhong (sagiko gmail com) (1 replies) RE: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 26 2008 02:08AM Brahnda A. Eleazar (brahnda e hermisconsulting com) (1 replies) RE: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 27 2008 07:39AM Adriano Leite (DHL CZ) (Adriano Dias Leite dhl com) (1 replies) RE: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 29 2008 02:33AM Brahnda A. Eleazar (brahnda e hermisconsulting com) Re: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 16 2008 05:08PM pand0ra (pand0ra usa gmail com) (1 replies) Re: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 16 2008 09:46PM pand0ra (pand0ra usa gmail com) RE: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 16 2008 12:39PM Newton, Preston (cpnewton eprod com) Re: Dangerous in using nmap for AS/400 730 machine configured with 3 ASPs? May 16 2008 07:08AM Jon Kibler (Jon Kibler aset com) RE: username and Password sent as clear text strings May 15 2008 12:33PM Shenk, Jerry A (jshenk decommunications com) Re: username and Password sent as clear text strings May 15 2008 03:12AM Todd Haverkos (fsbo haverkos com) (1 replies) RE: username and Password sent as clear text strings May 15 2008 02:34AM Shenk, Jerry A (jshenk decommunications com) |
|
|
Privacy Statement |
Since I haven't seen anything like that before, I would like to open a
discussion on what problems you have caused on production environment while
performing pen-testing.
From the e-mail of our colleague Brahnda sent few days ago, I see that small
unpredictable situations might rise even when we thing everything is under
control. :)
It would be nice to hear your "issues", maybe we can use the mail thread as
a checklist in the future to not cause any chain (Butterfly effect) problems
when performing pen tests.
Below I list some unexpected situations myself and colleagues witnessed
throughout our careers, when being pen/stress-tested by third parties:
- Scanning of web application with automated tools: Some pages can contain
forms for e-mail submittal. If SQL Injection brute force attack is performed
in such a page, you can either clog a vital business mailbox with trash, or
cause a DoS if smtp relay crashes.
- Port scanning of production servers - some IP stacks are not able to
handle even "simple" port scans. Services can hang (RPC in our case). Issues
are known with AS/400, HPUX and Solaris OS.
- stress-testing using windows XP: I once got a report from a Microsoft
Certified Partner that our e-commerce website couldn't handle more than 100
connections simultaneously. After sending developers, network architects and
security specialists to verify what was happening, it was found that the
operation system used for the scan was windows XP, which couldn't handle
more than 10 connections at once... and yes, the guy was MCSE... :)
It is always good to share experiences, even the bad ones :)
Adriano
0? *?H?÷
?0?10 +0? *?H?÷
?¥0?Î0?¶ ¡³0
*?H?÷
0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA0
071114143344Z
081113143344Z0?10U
dhl.com10
Uprg-dc10 Uea10UAdriano Leite (DHL CZ)1)0' *?H?÷
Adriano.Dias.Leite (at) dhl (dot) com1 [email concealed]0
?&??ò,daleite0?0
*?H?÷
0?ÐþrÛü=MlÙÔJß'ù[&ALP$é®1é?CøØ!ñ?$Ç?ï¯EY~_â*ÿ?½§ æO<? ü¨å@¶P£?ËÝqÒçw9>ªã¦éüh_ù6ìÜÛoâ?y×?³]¶ã_?2qyUþ^§µÌV?±ß?ö®×X´7£Ð0Í0 `?H?øB 0Uÿà0%U0Adriano.Dias.Leite (at) dhl (dot) com0 [email concealed]
U#0?=¸î½Ü6và$QMËe»Ôp05+)0'0%+0?http://amcm
s.dhl.com/ocsp0)U%"0 ++
+?7
0
*?H?÷
???Æá³ÈÄkÊ7H;? M§*?¹@l$ãþ«±Qò?1o?#
ô,fU??Çd§°þ? w?wpQ&?Êæ$?G¿DƹpZ?xÎÅ
QXYbç5ÒÕ»È?6Jö?dZÒ$FáÿÒ?aASIww}tzZøµÎ^tÕª??ª?Ãh £u?«zbjîó F7ì)©¢?zÛ]±?uþs&å^H¨·-ä%?ååºüÀ¹ØÕÁ¢??4OX¡jü+?ócL ÐìÑ?à? ÄO5y08EáÄ?tܺöö?lL~ì§r¡!?V???0?Ï0?· 0
*?H?÷
0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA0
010529070000Z
110529070000Z0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA0?"0
*?H?÷
?0?
?±vkÞ/ÚÞ¾Ú¦?\Ùêz¸
Cnv¶N8L/Yï]½ûä?Ô%?ø?yåj?ù??ÅÈÐ???oÐ?¦E¹üðG?òñZç,â P¶?SÊ)?sì)¿,T?¨QÚ!Ofï]gú©ÃƸ
?eµW
æ=?
BÒ=Ê?õjq¸h¨p?\päun§Év·»!ÂvÑÓ¸F¨üNÛ7¢ô;;!Ä";WV«?©Tʤ)ä?~J/ØRÃÃÂa6¹
óç?3Ôm\®£]
fQ½Ç±èÌ'Þg^rõNÚJÖV?M biø?lVû@?ªG+G-ÂD?̹£v0t0 `?H?øB0Uÿ0ÿ0U=¸î½Ü6và$QMËe»Ôp0U#0
?=¸î½Ü6và$QMËe»Ôp0Uÿ?0
*?H?÷
?_V?8??%XÌèI³ÁóG?Sr¨µ¸?Fð^ëKÔ¯c-óX?áð^Þ@$°¥ëM
¬ñÝF°çô?7Ðl?Ûw+AM1O-?ÊÎ;8?Ôɬ¡>xÖʧJ5>$óB5/@}ÍŸC%Ë?ÍñÕL?i_ã\Q¿´ÚÇù
7ÑéXH?ÄcɤTÈ??LùµeÇíÜ*?8Æð^?Üc<;HWU*`²ø~Ì?ãbKf¹?#eIßróòK?Z¹1o¹ö
ZºÉTqì[um ö
îYÎw?ÖäN*qêF??ϺÖ?=g?P?A;pJ?ÇZäkôô]rÉ o1?ø0?ô0v0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA¡³0 + ?Ø0 *?H?÷
1 *?H?÷
0 *?H?÷
1
080527081013Z0# *?H?÷
1c®÷©8VË:Qümûó]ö¤?0g *?H?÷
1Z0X0
*?H?÷
0*?H?÷
?0
*?H?÷
@0+0
*?H?÷
(0+0
*?H?÷
0? +?71x0v0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA¡³0?*?H?÷
1x v0o10 UUS10U
California10U
Burlingame10
U
DHL10USystems10U
DHL Global CA¡³0
*?H?÷
???NØ5Û&(Äá)J¸J¨ïÛú¯ED?µ±?Æ×pSFëÉûNÐ?Ø?XZ@ÝñÍme-·?ioÓå¢??î hü(3¶?ó=ì?§6'2áoÖq¢ñÕ%ÓÕwìA?ÒÉ?¿KR??Ù±]¾??$¶{ÿa´
${n×Lùê$?k
[ reply ]