Penetration Testing
Penetration Testing Services Aug 02 2010 11:18AM
cribbar (crib bar hotmail co uk) (11 replies)
Re: Penetration Testing Services Aug 10 2010 04:44PM
cribbar (crib bar hotmail co uk)
Re: Penetration Testing Services Aug 08 2010 11:36AM
MAlMozaiyn alfransi com sa (1 replies)
RE: Penetration Testing Services Aug 09 2010 06:24AM
Khalid Lakdawala (k lakdawala arbahcapital com)
Re: Penetration Testing Services Aug 03 2010 04:40PM
Andre Gironda (andreg gmail com) (1 replies)
Re: Penetration Testing Services Aug 15 2010 09:18PM
Richard Miles (richard k miles googlemail com)
Re: Penetration Testing Services Aug 03 2010 03:56PM
k.x86 (kanto 86 hotmail it)
RE: Penetration Testing Services Aug 03 2010 03:36PM
Jason Hurst (Jason Hurst PandaRG com)
RE: Penetration Testing Services Aug 03 2010 03:35PM
Hugo V. Garcia R. (hugo garcia infocenter com bo)
Re: Penetration Testing Services Aug 03 2010 01:44PM
Robin Wood (robin digininja org)
Re: Penetration Testing Services Aug 03 2010 11:41AM
Todd Hughes (thughes xdefenders com)
You need to understand the distinction between pen-testing and
vulnerability scanning. In simplest terms:

1) Vulnerability scanning (nessus, nmap, etc.) is akin to walking around
your facility, jiggling doorknobs and poking your head into the unlocked
offices, reporting back which doors are unlocked and which offices have
file cabinets in them.

2) Pen-testing is akin to entering your facility without being detected,
finding an unlocked door, entering that office, and then gaining access
to sensitive documents stored within the locked file cabinet inside that
office.

Almost anybody can do #1 but #2 requires a specific skill set.

cribbar wrote:
> Penetration Testing Community - I am interested in getting an expert response
> to a discussion that keeps raising up in our company.

--
Todd Hughes
Senior Security Analyst
CISA, CISSP
xDefenders, Inc.
1100 Pittsford-Victor Rd.
Pittsford, NY 14534
phone:(585) 385-2770 x7451
fax:(585) 385-3511
thughes (at) xdefenders (dot) com [email concealed]

"Distrust and caution are the parents of security"
--Benjamin Franklin

------------------------------------------------------------------------

This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------

[ reply ]
RE: Penetration Testing Services Aug 03 2010 08:24AM
Mathew Sealy (mat shj co uk)
RE: Penetration Testing Services Aug 03 2010 07:14AM
Sherif Eldeeb (archeldeeb gmail com) (1 replies)
Re: Penetration Testing Services Aug 03 2010 06:49PM
Justin Klein Keane (justin madirish net)
Re: Penetration Testing Services Aug 03 2010 07:04AM
BMF (badmotherfsckr gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus