Educause Security Discussion mailing list archives

Re: Pen Test vendors


From: "Jay Tumas BSEE, NSA IAM/IEM" <jay_tumas () HARVARD EDU>
Date: Fri, 9 Jan 2009 16:04:01 -0500

Hi Marty - The team at Foundstone (www.foundstone.com) would be happy to
provide this level of involvement.

Jason Bevis (Jason.Bevis () Foundstone com) would be the guy to start with.

Happy New Year to All!

J

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Jay Tumas - BSEE, NSA/IAM&IEM
                      ~~~~~~~~~~~~~~~~~~~~
- Network Operations, Security and Incident Response Team Manager
- Longwood Medical Area Technical Subcommittee Chair
                      ~~~~~~~~~~~~~~~~~~~~
       Harvard University - UIS/Network Operations Center
                  60 Oxford Street, Suite 132
                      Cambridge, MA. 02138
                      ~~~~~~~~~~~~~~~~~~~~
       Office: 617-496-8500  Mobile Device: 617-733-6169
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"The first method for estimating the intelligence of a ruler is
to look at the men he has around him." - Niccolo Machiavelli



Peterman, Martin (mdp4s) wrote:

Hey Randy,

How is Florida?

I am looking to build my network skills and would like to observe a
penetration test, i.e., be with the tester while it is going on.  Do
you know anyone who would be willing to do that with me?

Thanks much,
Marty

Marty Peterman, CISSP
peterman () virginia edu
Information Security Analyst
Information Security, Policy, and Records Office (ISPRO)
Office of the Vice President/CIO
University of Virginia, 2400 Old Ivy Rd.                 Phone
434.243.4909
Box 400898, Charlottesville, VA 22904-4898               Fax
434.243.9197
http://www.itc.virginia.edu/security/


-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of randy marchany
Sent: Friday, January 09, 2009 12:22 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Pen Test vendors

The crew at InGuardians,com are excellent. www.inguardians.com is the
www site. Their staff include current and former SANS instructors and
authors, the author of the La Brea tarpit IDS.

Randy

On Fri, Jan 9, 2009 at 11:04 AM, Anand S Malwade
<Anand.Malwade () shu edu> wrote:
>
>
> Hello All,
>
>
>
> We want to conduct an independent Penetration Testing to evaluate the
> effectiveness of our controls. Can anyone recommend a good Vendor
that you
> may have worked with in the past that really know their stuff and
exploit
> vulnerabilities discovered?  There are many rookies out there who
just print
> Nessus or Nmap scan output which we can do ourselves.
>
>
>
> Thanks,
>
> Anand
>
>
>
> Anand Malwade
>
> Information Security Officer,
>
> Seton Hall University
>
>
>
>


Current thread: