pen-test
[Top] [All Lists]

Re: Info about Pen Testing

To: pen-test@securityfocus.com
Subject: Re: Info about Pen Testing
From: Christoph Puppe <puppe@hisolutions.com>
Date: Sat, 10 Mar 2007 14:13:29 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <7.0.1.0.2.20070307160654.02642fd8@deadset-tech.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <7.0.1.0.2.20070307160654.02642fd8@deadset-tech.com>
Resent-date: Sat, 10 Mar 2007 21:16:04 -0700 (MST)
Resent-from: pen-test-return-1078483747@securityfocus.com
Resent-message-id: <20070311041604.CDF751440F5@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2) Gecko/20070222 SeaMonkey/1.1.1
Salve,

I've started, 8 years ago, by reading from start to end the accumulated
volumes of "Hacking Exposed". Just by understanding past exploits, you can
see the various vectors of intrusion. Then you need to try a lot of the
stuff in this books, get a VMWare Workstation with many different targets
and hack them. Put a firewall between you and the targets to get a more
real live experience. Then read full-disclosure and bugtraq to learn about
new stuff. Read and analyse the exploit code found for example in
metasploit. Subscribe to feeds from it sec sites, to get new papers on new
vectors and types of exploits. Loads of stuff to try in your lab.

Ah, and the first two volumes of "How to own the ..." are very good as
well. Next books depend on what you specialize. Get the books that help you
to understand the services you want to attack in depth. Hacking is imho
always an example of understanding a software better than the programmers
of said binary.

Good luck ;)

Gerrit @ DeadSet Internet Technologies wrote:
> Hi
> 
> I am new to the list so if I ask the wrong the wrong questions or in the
> wrong way, please excuse me ;)
> 
> I have recently done the CEH course, but what I would like to know is
> what the best way is to actually learn the skills required to do
> penetration testing. I know that actual practice is best, but are there
> any good material like tutorials that can assist in this learning process.
> 
> Thank you in advance
> 
> GK
> 

-- 
Mit freundlichen Grüßen

Christoph Puppe
Security Consultant


We secure your business.(TM)
_______________________________________________________

HiSolutions AG     Phone:    +49 30 533289-0
Bouchéstrasse 12   Fax:      +49 30 533289-99
D-12435 Berlin     Internet: http://www.hisolutions.com
_______________________________________________________

Mindestinformationen im geschäftlichen E-Mail-Verkehr nach §37a HGB:

Sitz der Gesellschaft / registered office:
Berlin

Handelsregistereintrag / Commercial register:           
Amtsgericht Berlin Charlottenburg - HRB 80155

Vorstand / Management Board:            
René Grosser,  Torsten Heinrich, Timo Kob, Michael Langhoff

Vorsitzender des Aufsichtsrates / Chairman of the supervisory board:
Prof. Dr. Klaus Müller

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>