Penetration Testing mailing list archives

RE: IPS arguments


From: "Shenk, Jerry A" <jshenk () decommunications com>
Date: Wed, 18 Feb 2009 17:07:08 -0500

Don't even TRY to penetrate the network unless you have approval from
the company.  Sounds like you don't...don't walk away from this one,
run!!

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Hugo Vinicius Garcia Razera
Sent: Saturday, February 14, 2009 9:35 AM
To: pen-test () securityfocus com
Subject: IPS arguments

Hello Gentleman's,

I have finished a penetration testing to a client like a month ago.
The company i worked for used some practices that i don't agree with.
that's one of the reasons i resigned. any way they managed to shell
the audited company a CISCO IPS using the results of the pen test.

Well the thing is that the CIO of that company is refusing to install
the IPS on their network even after his company has already put a buy
order for the equipment and said IPS is know on their building but he
refuses to install such equipment, augmenting that it is totally
unnecessary because they all ready have an Microsoft ISA server
Firewall in place, and symantec enpoint protection on the clients
machine.

Can any one point me why, they need an IPS?

The old company i worked for wants me to penetrate their network, to
proof them they need an IPS . this time I'm thinking on deploying an
old Trojan i coded.

but i would like to have more compelling arguments on why some one needs
an IPS

thanks for the time replying to my questions

Hugo



**DISCLAIMER
This e-mail message and any files transmitted with it are intended for the use of the individual or entity to which 
they are addressed and may contain information that is privileged, proprietary and confidential. If you are not the 
intended recipient, you may not use, copy or disclose to anyone the message or any information contained in the 
message. If you have received this communication in error, please notify the sender and delete this e-mail message. The 
contents do not represent the opinion of D&E except to the extent that it relates to their official business.



Current thread: