Educause Security Discussion mailing list archives

Re: Penetration Testing


From: "Barton, Robert W." <bartonrt () LEWISU EDU>
Date: Wed, 31 May 2017 16:46:27 +0000

We have done a POC here (I was not the professor).  The students were asked to “look around”, and try to think like a 
hacker as part of individual class projects.  The best three did find some interesting things, but I would say there 
focus would need to be refined to make it a better project, make it a team project, and the time given needs to 
increase (e.g. what is a good item to attack; the wireless network you found, or the web site, based on 
time/resources?).  Maybe too much freedom for somebody beginning this type of discovery…?  Send me an email privately 
if you want to talk more about it.

The Bradley course did a large scale attack; enumeration through social engineering.  It was a full semester long.

Robert W. Barton
Director of Information Security
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Mike 
Cunningham
Sent: Wednesday, May 31, 2017 11:35 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Penetration Testing

Have you ever had your own students do a penetration test against the University systems?  Both inside and out?


Mike Cunningham
VP of Information Technology Services/CIO
Pennsylvania College of Technology



From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Barton, 
Robert W.
Sent: Wednesday, May 31, 2017 12:18 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Penetration Testing

Bradley University has a class on penetration testing; they did a “red team” attack against an outside company.  The 
idea was to do outside and inside the following year (they had to get people on-board).  They did a presentation at 
ForenSecure this year.

Robert W. Barton
Director of Information Security
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of David 
Santos
Sent: Wednesday, May 31, 2017 11:03 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Penetration Testing

Hi All,

We do one every couple years by an outside vendor but we would like to start doing more on our own; possibly every 6 
months.  So, I’m looking for any penetration testing plans or the process used for conducting pen testing on your own. 
Any thoughts or ideas welcomed, thanks again.

Looking forward to your responses.

Have a Great Day!

David Santos
IT Security & Helpdesk Manager,
Information Technology

[cid:image001.jpg@01D2DA03.89576990]

Felician University
262 South Main Street
Lodi, NJ 07644
P: 201-559-6075
www.felician.edu<http://www.felician.edu>


______________________________________________________________________
This outgoing email has been scanned by the MessageLabs Email Security System for Felician University.
_____________________________________________________________________

This message (including any attachments) is intended only for the use of the individual or entity to which it is 
addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from 
disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you 
are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. 
If you have received this communication in error, notify us immediately by telephone at (815)-836-5950 and (i) destroy 
this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you.

________________________________
This email may contain confidential information about a Pennsylvania College of Technology student. It is intended 
solely for the use of the recipient. This email may contain information that is considered an “educational record” 
subject to the protections of the Family Educational Rights and Privacy Act Regulations. The regulations may be found 
at 34 C.F.R. Part 99 for your reference. The recipient may only use or disclose the information in accordance with the 
requirements of the Federal Educational Rights and Privacy Act Regulations. If you have received this transmission in 
error, please notify the sender immediately and permanently delete the email.

This message (including any attachments) is intended only for
the use of the individual or entity to which it is addressed and
may contain information that is non-public, proprietary,
privileged, confidential, and exempt from disclosure under
applicable law or may constitute as attorney work product.
If you are not the intended recipient, you are hereby notified
that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at (815)-836-5950 and
(i) destroy this message if a facsimile or (ii) delete this message
immediately if this is an electronic communication.

Thank you.


Current thread: