Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

Re: Choosing a firewall (was Re:firewall suggestion)

Subject: Re: Choosing a firewall (was Re:firewall suggestion)
Date: Thu, 24 Feb 2005 01:16:34 -0600
On Wed, 23 Feb 2005 22:39:33 -0500, Bob Noxious <b.noxious@gmail.com> wrote:
Why haven't we seen a similar audit of PIX or Netscreen, in all these years?

Does anyone REALLY know if PIX or Netscreen aren't swiss cheese already?

Let's find out.
Juniper just handed me a Netscreen 25 eval unit, no strings, no NDA,
I just have to give it back in (physically) undamaged condition in 60 days.


What tests would you like to see run against it?  My first step will be ISIC
and the other "usual suspects", but after that (and Mike's TCP shenanigans),
I'm not sure what else would make sense to throw at it.  Authentication is
always a good vector to go after, worked great for me in the past :)

I was *supposed* to buy a license for Immunity Canvas to help kick this
off (seems like a good place to start beating on "Deep Inspection" claims),
but that got axed out of my first quarter budget, and might not make
it into the second...

Suggestions?


Kevin Kadow

<Prev in Thread] Current Thread [Next in Thread>