Penetration Testing mailing list archives

Re: LAN pen test


From: killy <killfactory () gmail com>
Date: Tue, 5 Dec 2006 20:20:19 -0500

you are not trying to SE us are you?

are you sure this isn't your corporate LAN at work?

:-)



On 12/4/06, mifa () stangercorp com <mifa () stangercorp com> wrote:
I have gone through the eh course and I still do not feel like I can really understand how to pen test.  None of the 
exploits or methods seem to work on a updated xp machine.  I set up a vm ware network to practice on.  I can not seem 
to make any progress because the information I have is outdated.

Can anyone point me to a resource that would help me gain access to an xp machine that is running automatic updates (my 
vm).  I cant seem to do it one the lan any way other than to use a trojan and what would be to point of pen testing a 
system if the only way in is via trojan; thats standard seucrity, dont run programs from email, blah blah blah...

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------




--
If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: