Security Basics mailing list archives

Re: External Pen Test / Manual Exploitation


From: Muhammad Faisal Rauf Danka <mfrd () attitudex com>
Date: Mon, 22 Sep 2003 16:49:16 -0700 (PDT)

Ofcourse, Or else don't you think it will be only an automated 
vulnerability assessment? Instead of Penetration Testing, nomatter how 
much you stretch the scope of it.

Although aspect of DoS on production servers should be carefully 
considered, since many automated scanners have a provision of excluding 
DoS tests, however the manual phase/ practice may overlook it. 

Regards
--------
Muhammad Faisal Rauf Danka



--- Jason Burzenski <jburzenski () americanhm com> wrote:
I am in the process of reviewing a proposal for external penetration 
testing
from a vendor.  One of the phases of the pen test includes a manual
exploitation of vulnerabilities discovered using automated scans.  The 
text
makes mention of specially crafted commands or code and the use of 
modified
open source tools.  

Is this a normal part of an external penetration test?  According to the
break down of phases, they will use automated tools, then verify the 
results
using manual means to reduce false positives.  Why the need for 
additional
manual exploitation?  This seems to pose unnecessary risk to my network
services.  

Jason Burzenski


_____________________________________________________________
---------------------------
[ATTITUDEX.COM]
http://www.attitudex.com/
---------------------------

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: