Penetration Testing mailing list archives

RE: Vulnerability Assessment of a EAL 4 system


From: "Marc Doudiet" <marc.doudiet () psdsecurite com>
Date: Wed, 1 Nov 2006 22:19:21 +0100

Hi,

I don't think that iptables is a criteria for EAL. I suggest you check
http://www.commoncriteriaportal.org/public/files/ccusersguide.pdf

Nist provide infos for common criteria.

Hope this helps.

Marc Doudiet 

-----Message d'origine-----
De : listbounce () securityfocus com [mailto:listbounce () securityfocus com] De
la part de castellan2004-fd () yahoo com
Envoyé : mercredi, 1. novembre 2006 11:12
À : pen-test () securityfocus com
Objet : Vulnerability Assessment of a EAL 4 system


I am looking at a Linux server which has been accredited as a EAL4 system by
IBM.  During the assessment, I was looking for standard Linux protections
like iptables, ssh etc.  On this server, there is no iptables.

Regardless, I would like to know how to evaluate a EAL
4 system.  What do you need to look for in the EAL 4 system in production
that could become vulnerable?

Thank you in advance for any help.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------

Attachment: smime.p7s
Description:


Current thread: