Penetration Testing mailing list archives

Re: Licensed Penetration Tester LPT


From: Mark Teicher <mht3 () earthlink net>
Date: Thu, 27 Apr 2006 17:09:31 -0400 (GMT-04:00)

I forgot about those areas of expertise.  
Must be able to reverse engineer popular network routing assembly code and present their findings in front of large 
audiences.
Must be able to afford legal representation
Must know r0cketgrl.. :)

-----Original Message-----
From: Gene Cronk <gcronk () trsg net>
Sent: Apr 27, 2006 1:27 PM
To: Mark Teicher <mht3 () earthlink net>
Cc: pen-test () securityfocus com, r0cketgrl () yahoo com
Subject: Re: Licensed Penetration Tester LPT

Yeah....expert in Cisco, Juniper
802.11
x86(64), PPC, Solaris, MIPS(el) hardware
SQL Injection (MSSQL, Access, MySQL, Postgres)
Form Validation
Assembly, C(++,#), Perl, Python, Ruby, PHP, ASP, CFM
Mainframes
Switches
TCP/IP (v4 and v6), AppleTalk, IPX/SPX, NetBEUI, Twinax
SSL/TLS
Proxies (including SOCKS4/5 and HTTP)

And honestly, is there anyone that meets all of these critera and
actually has a life (I'm hoping Mark was being facetious to a certain
extent)?
--
Gene Cronk CISSP-ISSAP IAM
Systems Administrator -- The Robin Shepherd Group
http://www.trsg.net
Office: 904-359-0981x3166  Cell: 386-795-3081


Mark Teicher wrote:
The story is very interesting, but it describes the reasoning for the licensing, and this email thread subject is 
very interesting, but no one has discussed the qualifications of becoming a licensed penetration tester ??


Do the person need to have experience with intrusion methods and assessment tools using:
ISS
SATAN
Nessus
Nmap
Snort
Ethereal
Scanrand
other?
Must know the difference between an XMAS scan and a NULL scan ?
Expert in social engineering
Expert in lockpicking (must have placed #2nd in local and national contests) ?
Expert in Security Policy Assessments
Expert at the kernel level for any and all Unix based operating systems ?
Must know what 'BIFF' stands for ?
Expert in PKI
candidate must have a minimum of 7+
years of network administration experience in multiple operating systems to include
Linux, Windows, Solaris, and BSD. 
Must be able to dress when required
Must be able to dress themselves 
Must be able to shower on a frequent basis
Must be an expert in shining their management on when requested

Did I miss anything ??
-----Original Message-----

From: xelerated <xelerated () gmail com>
Sent: Apr 26, 2006 4:54 PM
To: Phil Frederick <flosofl () gmail com>
Cc: pen-test () securityfocus com
Subject: Re: Licensed Penetration Tester LPT

Actually, you have to be a licensed Private Investigator,
not a certified pen tester.

I think it was on the register's site.

On 4/26/06, Phil Frederick <flosofl () gmail com> wrote:

This is happening now.  Georgia has pending legislation for forensic
examination of information systems.  If you aren't licensed as an
Investigator in the state, you can be charged with a felony if the law
passes.

I can't find a link, but I swear I read this a couple days ago.
Anyone have any info, or was I hallucinating :)

On 4/25/06, v b <r0cketgrl () yahoo com> wrote:

All funning aside, this was included in a topic of a
BoF at the recent ShmooCon held in DC.  The speakers
contended that unless the community becomes
self-policing, there WOULD eventually be government
legislation to license information security
practitioners.  Interesting theory.  I like the idea
of shipping all unlicensed practitioners to Lincoln.
Could do wonders for that local economy. :-)

Regards.


--- Dogten <dogten () d3fcon org> wrote:


Mark Teicher wrote:

Why not license security engineers/gurus like they

do social workers, plumbers and doctors.

Then after one gets everyone to comply, partner

with an insurance company to offer liability and
malpractice insurance to the licensed penetration
testers, just in case someone accidently shuts down
a life support system in a hospital as they are
scanning random Class 'C's on the internet or
hijacking root DNS servers in order to play audio
streams.

For those who do not comply, set up Senate

hearings, and send out letters to those who do not
comply, "Are you an unlicensed penetration tester?"
If yes, please list all your friends, neighbors, etc
that may or may not be unlicense penetration
testers.  Once they have rounded up all the non
complying penetration testers, escort them to local
train stations, and guide them onto the train, where
they will be taken to re-education camps in Lincoln,
Nebraska.  --:)


-----Original Message-----


From: Dogten <dogten () d3fcon org>
Sent: Apr 20, 2006 10:08 PM
To: Steve Friedl <steve () unixwiz net>
Cc: pen-test () securityfocus com
Subject: Re: Licensed Penetration Tester LPT

Steve Friedl wrote:


If it's not from the government, it's not a real

license.

where does literary license come in? the media

certainly practices it

with impunity.

--
-dogten, C?ISSP
_________________
Fight the power and the power will fight back
Your only as good as the system you hack
If you become a problem you will be replaced
Banned, shut down, erased !




------------------------------------------------------------------------------

This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the

only one to win the Analyst's

Choice Award from eWeek. As attacks through web

applications continue to rise,

you need to proactively protect your applications

from hackers. Cenzic has the

most comprehensive solutions to meet your

application security penetration

testing and vulnerability management needs. You

have an option to go with a

managed service (Cenzic ClickToSecure) or an

enterprise software

(Cenzic Hailstorm). Download FREE whitepaper on

how a managed service can

help you:

http://www.cenzic.com/news_events/wpappsec.php

And, now for a limited time we can do a FREE

audit for you to confirm your

results from other product. Contact us at

request () cenzic com for details.

------------------------------------------------------------------------------






Shhhh, they'll see us.

--
-dogten, C?ISSP
_________________
Fight the power and the power will fight back
Your only as good as the system you hack
If you become a problem you will be replaced
Banned, shut down, erased !




------------------------------------------------------------------------------

This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only
one to win the Analyst's
Choice Award from eWeek. As attacks through web
applications continue to rise,
you need to proactively protect your applications
from hackers. Cenzic has the
most comprehensive solutions to meet your
application security penetration
testing and vulnerability management needs. You have
an option to go with a
managed service (Cenzic ClickToSecure) or an
enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how
a managed service can
help you:
http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit
for you to confirm your
results from other product. Contact us at
request () cenzic com for details.


------------------------------------------------------------------------------




__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------





------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? 
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's 
Choice Award from eWeek. As attacks through web applications continue to rise, 
you need to proactively protect your applications from hackers. Cenzic has the 
most comprehensive solutions to meet your application security penetration 
testing and vulnerability management needs. You have an option to go with a 
managed service (Cenzic ClickToSecure) or an enterprise software 
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can 
help you: http://www.cenzic.com/news_events/wpappsec.php 
And, now for a limited time we can do a FREE audit for you to confirm your 
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: