Penetration Testing mailing list archives

Re: [PEN-TEST] Please educate the client....


From: "Dude, Bacano" <bacano () ESOTERICA PT>
Date: Thu, 14 Sep 2000 15:25:21 GMT

Hi2all,

There are two problems in educating a client:
1. Does he want/allow to be educated? does he have an open mind?
2. Who is educating? does it have education him self?

This two problems can conduct to a 3rd, that is, how much time is
available for the education issue? Are classes included?

This probably can end in one point: are we testing the computers or
the people who are working with those computers? i suppose both areas
can't be left out.

Does scanners and sniffers capture the brain of a sysadmin?

Like, try to do a penetration test just by, anyhow, put that sysadmin
crazy in a way that, no mather how good he is, he will start to make
mistakes (killing his golden fish and poisoning his white cat *are*
options).

Mom's question: in pen-testing (= legal, ethical and polite tests)
who works that way? you can be sure that there are hackers that work
that way...

Doesn't matter who i'm or what i do, just think a little (also) about
this ...My only elite skillz are about pizzas. Now, think again in
what i said.

A pen-test is not an end, is just a beginning of an never ending job.

[  ]'s bacano


---------------------------------------------
Esta mensagem foi enviada usando o WebPOP II.
http://www.via-net-works.pt/email


Current thread: