Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

PCI Compliance (Vulnerability Scans)

Subject: PCI Compliance (Vulnerability Scans)
Date: 16 Dec 2006 19:09:51 -0000
Group,

Have any of you performed simply PCI compliant Vulnerability Scans? if so, I am 
looking for a few things:

1.  Did you use an automated Scanner (only)? If so, which one (or which one do 
you think is the best)?
2.  What are your recommendations for performing a simple PCI compliant Scan? 
Is an automated tool the best solution for a simple scan? I assume it is, since 
I don't believe much manual time/effort should be devoted to them, as opposed 
to a real Vulnerability Assessment (manual verification)/Penetration Test.

3.  Could someone also guide me in the right direction for finding out more 
about PCI compliment vulnerability scanning (i.e. websites, books, whitepapers, 
etc)?
 - I am wondering specifically while doing discovery scanning do you only focus 
on ports 22,23,25,80 and 443 and if found "alive" perform a full 65k+ scan on 
those hosts.  Also, do you only perform scans on hosts that provide sensitive 
information like servers? Would routers, etc that connect these servers count 
as well?

Anyway, Thanks allot for any information anyone can provide.

Sparky

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>