Security Basics mailing list archives

[Spam] Re: Server Penetration Testing


From: Gichuki John Chuksjonia <chuksjonia () gmail com>
Date: Sat, 24 Sep 2011 08:08:37 +0300

I would advice you to stop automated Pentest, and think like an evil
hacker would, and go manual.




On 9/23/11, Femi Mogaji <olufemimogaji () gmail com> wrote:
Hi list,

So we just had our annual audit, and one of the findings that came up is
server-side pen-tests. We already carry out quarterly ASV scans & yearly
pentest of our external IP addresses, where we fell short was the lack of
internal pentests. The question is: what tools can I use to carry out these
tests? Especially tests directed at SQL servers & file servers etc. A tool
that can generate easy to read reports would be really nice. Any input will
be appreciated.

Thanks in advance,

Femi
Sent from my BlackBerry® smartphone provided by Airtel Nigeria.


-- 
-- 
Gichuki John Ndirangu, C.E.H , C.P.T.P, O.S.C.P
I.T Security Analyst and Penetration Tester
jgichuki at inbox d0t com

{FORUM}http://lists.my.co.ke/pipermail/security/
http://chuksjonia.blogspot.com/

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: