Penetration Testing mailing list archives

Limited vs full blown testing


From: Toby Barrick <TBLinux () covad net>
Date: Wed, 23 Jun 2004 09:27:58 -0700

All,

During my many years of pen testing one common thread when dealing with customers has been the request to not perform any destructive or DOS type testing. When I speak of DOS, I'm not talking about DDOS, I'm talking just a single machine and the tests that can be accomplished with that machine. IMHO abiding by that request is really short changing the customer and skewing the results. Additionally a lot of companies don't want their applications poked at either.

What has been the experience of the members on this list? Do you just gleefully accept the check and any limitations imposed on testing or do you push for a "complete" suite of tests?

Thanks in advance!

T


Current thread: