Penetration Testing mailing list archives

Re: Issues using Nipper with Checkpoint configuration


From: Joshua Gimer <jgimer () gmail com>
Date: Fri, 3 Apr 2009 09:57:29 -0600

Just an FYI: Firesec is priced around $1,000 per install.

On Tue, Mar 31, 2009 at 3:50 AM, Nikhil Wagholikar
<visitnikhil () gmail com> wrote:
Hi Amardeep,

You can have a look at tool 'Firesec' as an alternative to Nipper.

More Info:
http://www.niiconsulting.com/products/firesec/Firesec_Datasheet_1.0.pdf
http://www.niiconsulting.com/products/firesec123/Firesec_Usage_Guide_v1.0.pdf

---
Nikhil Wagholikar
Practice Lead | Security Assessment & Digital Forensics
Network Intelligence (I) Pvt. Ltd. [NII Consulting]
Web: http://www.niiconsulting.com/
Comprehensive Information Security Training
http://www.niiconsulting.com/services/education/Training%20Calendar.html


2009/3/24 Amardeep Singh <Amardeep_Singh () symantec com>

Hi All,

I tried using a very good audit tool named: Nipper against my cisco
router and checkpoint (nokia base) firewall configuration.

I got good results for my router but for firewall I had 200+ rules on my
enforcement module but some how I am getting audit result for 92 of them
using Nipper. I tried checking nipper.ini file for customization, but
unable to get +ve outcome.

Could somebody help?

Amardeep Singh

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Learn all of the latest penetration testing techniques in InfoSec Institute's Ethical Hacking class.
Totally hands-on course with evening Capture The Flag (CTF) exercises, Certified Ethical Hacker and Certified 
Penetration Tester exams, taught by an expert with years of real pen testing experience.

http://www.infosecinstitute.com/courses/ethical_hacking_training.html
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year? Check out the online penetration testing 
courses available at InfoSec Institute. More than a boring "talking head", train in our virtual labs for a total 
hands-on training experience. Get the certs you need as well: CEH, CPT, CEPT, ECSA, LPT.

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------





-- 
Thx
Joshua Gimer

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year? Check out the online penetration testing 
courses available at InfoSec Institute. More than a boring "talking head", train in our virtual labs for a total 
hands-on training experience. Get the certs you need as well: CEH, CPT, CEPT, ECSA, LPT.

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------


Current thread: