Security Basics
Disabling IPS for PENTEST Aug 06 2012 01:57PM
Kid Tangerine (kidtangerine gmail com) (7 replies)
Re: Disabling IPS for PENTEST Aug 06 2012 05:01PM
RobOEM (rd seclists gmail com)
Re: Disabling IPS for PENTEST Aug 06 2012 04:49PM
gig (gigabit satx rr com)
Re: Disabling IPS for PENTEST Aug 06 2012 03:11PM
Reginald%20Wheeler (wheeler90 comcast net)
Re: Disabling IPS for PENTEST Aug 06 2012 02:48PM
Shane Anglin (shane anglin gmail com)
Re: Disabling IPS for PENTEST Aug 06 2012 02:44PM
Alun Morgan (alun d morgan gmail com)
Re: Disabling IPS for PENTEST Aug 06 2012 02:18PM
haZard0us (hazard0us pt gmail com) (3 replies)
Re: Disabling IPS for PENTEST Aug 06 2012 02:54PM
Rajiv D (rajiv ceh gmail com)
Hi,

For blackbox, greybox testing, NO. But for whitebox, you MAY if its an internal one not the internet facing.

-- Rajiv

-----Original Message-----

From: haZard0us <hazard0us.pt (at) gmail (dot) com [email concealed]>

Sender: listbounce (at) securityfocus (dot) com [email concealed]

Date: Mon, 6 Aug 2012 15:18:46

To: Kid Tangerine<kidtangerine (at) gmail (dot) com [email concealed]>

Cc: <security-basics (at) securityfocus (dot) com [email concealed]>

Subject: Re: Disabling IPS for PENTEST

I don't have any experience, but I think that disabling the IDS/allowing their IP is wrong.

The main purpose of a pen test is to assess the vulnerabilities on your system. An attacker has to deal with the IDS. If you disable for them, just makes their job easier.

If I were the one to decide, I would say no.

But, once again, I got no experience.

A 06/08/2012, às 14:57, Kid Tangerine escreveu:

> All,

>

> Corporate has requested we get a PENTEST for our Internet facing

> website from a third party, but the third party asked us to allow

> their ip address to be excluded from our IPS.

>

> Is that a common practice to basically turn off our protection and

> allow them in?

>

> Obviously we aren't developers, so If the code has sql injections,

> cross site scripting, etc vulnerabilities we cannot fix it within the

> corporate guidelines, and our only leverage from the IT infrastructure

> side is to include the needed filters in the IPS to prevent their

> crappy code from being exploited. It we turn off the IPS I am sure all

> kinds of things will show up.

>

> Any experience appreciated.

>

> ------------------------------------------------------------------------

> Securing Apache Web Server with thawte Digital Certificate

> In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

>

> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1

> ------------------------------------------------------------------------

>

------------------------------------------------------------------------

Securing Apache Web Server with thawte Digital Certificate

In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1

------------------------------------------------------------------------

[ reply ]
RE: Disabling IPS for PENTEST Aug 06 2012 02:42PM
Wells, Sean (Sean Wells avistacorp com)
Re: Disabling IPS for PENTEST Aug 06 2012 02:36PM
Jose Fuertes (jfuertes alaver com do) (1 replies)
Re: Disabling IPS for PENTEST Aug 06 2012 03:58PM
Mike Kallies (mike kallies gmail com)
Re: Disabling IPS for PENTEST Aug 06 2012 02:14PM
khushal201301 gmail com


 

Privacy Statement
Copyright 2010, SecurityFocus