Penetration Testing mailing list archives

Re: Lab OS Choices


From: Jan Heisterkamp <janheisterkamp () web de>
Date: Fri, 17 Aug 2007 08:30:06 -0600

Pete Herzog schrieb:
Hi,

Booting from a Live Linux CD is the way to do it. Running it virtually is not only a huge mistake but a disservice to the client. Your job is to look at security under a microscope and by adding more layers of abstraction you may as well be standing on a ladder and peering down into the microscope with binoculars. You cannot get the same packet results consistently with a virtual machine that you will with the original OS on metal.

It's a mix of aquired slothfulness and incompetence of the Mc. Donalds fast-food generation. All has to be pre-prepared, preferably without spending any effort to reach the objective. Just push the button and everything is like before. Virtualization is a simulation of a possible reality. Until we can't say and proof that vitualization is an ecaxt mirror or 1:1 image of reality, it's not possible -and in my opinion a disreputable abuse of the customers belief - to use VEs on the job.
Please enjoy your fishburger...now!

Regards,
Jan



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: