Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Pen Test Success Factors |
|---|---|
| Date: | 25 Feb 2008 02:03:55 -0000 |
You could always offer fixing the exploits and vulnerabilities. That would truly be a great success factor they would love. You could indeed generate a full report of all events that took place with custom comments to IT staff/administrators in pointing out problems, suggestions, and common feedback. Also, you might want to expand your findings with the additional testing of odd behaviors or functionalities by testing for SSL and changing HTTPS protocols to boost your results and raise the customers confidence, and of course security. Also, you should if you have not already, test for logical flaws, which have to be done manually and explained throughly, and can be quite effective, and is almost exactly what the customers want to hear, because of the non-technical terms involved to demonstrate or explain the attack(s). You should also explain that every bit of exploit or vulnerability is important. Don't let them justify that XSS isn't serious, (which most company's do). Expl ain to them that every bit of information assembled is indeed quality for an attacker. Also, you should speak with the CTO or the IT Staff so that they can better understand your concerns, as most business owners, just don't because of the lack of security information and what is normally embedded. -Yousif Yalda -Security Consultant -Http://Vapt-Sec.Com -Http://YousifYalda.BlogSpot.Com ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Fwd: How to report a Vulnerability to a Company, Yousif |
|---|---|
| Next by Date: | RE: Pentesting tool - Commercial, Trygve Aasheim |
| Previous by Thread: | Re: Fwd: How to report a Vulnerability to a Company, Yousif |
| Next by Thread: | RE: testing an installer, Van Meter, Micheal |
| Indexes: | [Date] [Thread] [Top] [All Lists] |