Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Why Penetration Test? |
|---|---|
| Date: | Tue, 14 Jun 2005 15:32:50 +0800 |
Tarun The Nut wrote:
Yes that's correct, the 'onion' approach, any vulnerability discovered must be mitigated against, including any vector which renders the vulnerability exploitable. It's something like risk assessment and business impact analysis, 'pen-test' itself tends to just conjour images of technical testing, 'ethical hacking' or whatever you want to call it.when i mentioned vulnerabilities that are exploitable, i meant not only being able to "exploit" the vulnerability but also map all the possible paths of attack.
Also by plugging a vulnerability does not necessarily means "patching"
but taking all possible steps (patches/tools/processes blah blah) that
can help mitigating a possible exploit of the vulnerability.
The question still remains: Pen Test will always depend on the skill
set of the company/individual contracted to do Pen Test and results
will vary from person to person (or company to company).
Thankx to Pete Herzog for bringing it out. It skipped my mind to include that in my previous mails.
Is it not feasible to assume that the real attacker will be able to
exploit the vulnerability using any one of the numerous attack paths
and go about ensuring the vulnerability is "plugged" based on the
phased approach described in one of my mails earlier?
My approach is generally:
Something along those lines anyway.
Cheers
-- Gareth Davies
Manager - Security Practice
www.mynetsec.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Why Penetration Test?, Tarun The Nut |
|---|---|
| Next by Date: | Useful skills for Web Penetration tester to have, lloyd |
| Previous by Thread: | Re: Why Penetration Test?, Tarun The Nut |
| Next by Thread: | Re: Why Penetration Test?, intel96 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |