pen-test
[Top] [All Lists]

Re: Re: Penetration test report - your comments please?

To: pen-test@securityfocus.com
Subject: Re: Re: Penetration test report - your comments please?
From: scott <redhowlingwolves@bellsouth.net>
Date: Mon, 30 Jul 2007 00:32:21 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <200105311722.NAA18047@ogion.hpdc.syr.edu>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <200105311722.NAA18047@ogion.hpdc.syr.edu>
Resent-date: Mon, 30 Jul 2007 02:23:12 -0600 (MDT)
Resent-from: pen-test-return-1078484731@securityfocus.com
Resent-message-id: <20070730082312.3014023751E@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 2.0.0.0 (X11/20070326)
This is sad state of management.Kind of like a restaurant  knowing when
the health inspectors are coming.Sad,but it happens.This is when the
tester *must* shine!!!~

Regards,
   Scott

Steve Chapin wrote:
>> What approach do most people here take? Generally, because the
>> client will depend on you to organize the testing, the choice is
>> *usually* yours. What do you think is the best method?
>>     
>
> We always ask that our activities be known by the minimum number of
> people (usually the CEO and Chief Security Officer of the client).
> If the front-line people know that there is a test underway, they
> will behave differently.
>
> sc
> --
> == Steve J. Chapin, President         ==
> == RedTeam Consulting Company, LLC    ==
> == chapin@ecs.syr.edu                 ==
>
>   


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>
  • Re: Re: Penetration test report - your comments please?, scott <=