Dailydave mailing list archives

RE: New presentation is up: 0days: How hacking reallyworks


From: "Maynor, David \(ISS Atlanta\)" <dmaynor () iss net>
Date: Tue, 1 Feb 2005 11:12:31 -0500


Assume the not-so-distant future (or present) is ruled by 0day, which
I totally agree with you on.  What is the value-added from
pen-testing/auditing?

It sounds like you have the wrong train of thought on this. The idea and
value behind pentesting is not to show that you can be popped by one
0day, its to expose architecture and design flaws in your applications
and network design. A correctly designed network should be able to
withstand one or two 0day in major applications and still stay useful.
If your infrastructure can be brought down by a single bug then you
should look long and hard at its design. 



_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: