| To: | pen-test@securityfocus.com |
|---|---|
| Subject: | Re: Pentesting Old unsupported Firewall Appliances |
| From: | Tiago Batista <tiagosbatista@gmail.com> |
| Date: | Wed, 13 Jun 2007 00:43:27 +0100 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | pentest-list2@consult.net |
| Delivered-to: | mailing list pen-test@securityfocus.com |
| Delivered-to: | moderator for pen-test@securityfocus.com |
| Dkim-signature: | a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:date:from:to:subject:message-id:in-reply-to:references:x-mailer:mime-version:content-type:content-transfer-encoding; b=pOiEh0CvXSrzv38AHrzuh04FQrtRMT/nbQYzi89SEsT8jBawaSpksIBzqLj3s689CUDQjTdvRKzpmvEriAHVX2sljIpIJnns7iZxeXHOOOqQfzwfhnqcBicMFX/Q2HHe8B7Q1l5gEkSyGSklcwZSXv9uMfyR+8wFKyvEt54nFG8= |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:date:from:to:subject:message-id:in-reply-to:references:x-mailer:mime-version:content-type:content-transfer-encoding; b=ejU+PLuvoGbGuPsrvd784Wal5Bfyjl/9rQp3tKLoimyQMsAP5TvwIHuhUjRGSFqfpPkoNnElYNFzDJQR4T+Wy0Vp2PLvg6DYimuB9764xYGVSurpHcR7DOUmxnSekakrDPIn3+xYYqzyVpLJN4GYu4LHMdBu7z8cESwnm1PPOK4= |
| In-reply-to: | <27589.67646.qm@web38403.mail.mud.yahoo.com> |
| List-help: | <mailto:pen-test-help@securityfocus.com> |
| List-id: | <pen-test.list-id.securityfocus.com> |
| List-post: | <mailto:pen-test@securityfocus.com> |
| List-subscribe: | <mailto:pen-test-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:pen-test-unsubscribe@securityfocus.com> |
| Mailing-list: | contact pen-test-help@securityfocus.com; run by ezmlm |
| References: | <27589.67646.qm@web38403.mail.mud.yahoo.com> |
| Resent-date: | Fri, 15 Jun 2007 10:44:12 -0600 (MDT) |
| Resent-from: | pen-test-return-1078484369@securityfocus.com |
| Resent-message-id: | <20070615164412.96AE11450FC@outgoing2.securityfocus.com> |
| Resent-sender: | listbounce@securityfocus.com |
| Sender: | listbounce@securityfocus.com |
On Mon, 11 Jun 2007 01:56:00 -0700 (PDT) Harold Castro <b0ydaem0n@yahoo.com> wrote: > > If all else fails, do you tell the customer that it is > safe to ignore those warnings and vulnerabilities > because you, on a hacker's perspective, was not able > to penetrate the network by making use of those > vulnerabilities found, that the hacker might have a > hard time as well and eventually opt for another > target? I am no security expert, but security by obscurity does not seem the way to go! The fact that you did not find any good documentation does not imply that some old hacker with a grudge against your client does not have the full docs in his basement! Tiago ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------ |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | MS Access+pen-test, wymerzp |
|---|---|
| Next by Date: | Re: Pentesting Old unsupported Firewall Appliances, Security Guy |
| Previous by Thread: | RE: Pentesting Old unsupported Firewall Appliances, Clemens, Dan |
| Next by Thread: | Firewall Leak Testing Was Re: Pentesting Old unsupported Firewall Appliances, mOses |
| Indexes: | [Date] [Thread] [Top] [All Lists] |