Dailydave mailing list archives

Re: New presentation is up: 0days: How hacking really works


From: pete <lists () isecom org>
Date: Tue, 01 Feb 2005 17:51:27 +0100

uh. 0days have always been about, nothing is going to 'change' and the

This is a very true statement.  A future of 0 days is the present now.
What needs to change now is the full function of penetration testing.
There is a very big need for penetration testing to do more than just
penetrate 50 ways to Sunday, mop up, and report.  Today's tester, should
not just be looking for known vulnerabilities and pumping 0 days, but
also looking for all the security limitations within the scope that
provide opportunity for 0 days, the impact of the breach, depth of the
attack, and reach of control.  Pen testing can provide value, even in a
world of 0 days, but that depends on what the tester is doing to provide
that value.

-pete.


_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: