-
06-20-2011, 05:22 PM #1Garage Newcomer
- Join Date
- Jun 2011
- Posts
- 2
- Thanks
- 0
- Thanked 0 Times in 0 Posts
Vulnerability Assessment and Penetration Testing
Hi guys,
A colleague recently asked me a question that left me stumped.
His client told him: 'we only need to do penetration testing and not vulnerability assessment. Since I am preventing threats coming in from outside using PT, I dont need to do VA.. Even if there are vulnerabilities inside, since no threat can come inside, I dont have to worry.'
I asked him convey the example of a virus spreading through an infected USB. Its able to spread havoc because internal vulnerabilities remain unaddressed.
Do you guys have any real life examples that can be used to convince his client?
-
06-20-2011, 05:26 PM #2Security Researcher

- Join Date
- May 2011
- Location
- Pune, Maharashtra, India
- Posts
- 226
- Blog Entries
- 1
- Thanks
- 75
- Thanked 91 Times in 50 Posts
just give to him a case study on how insiders are bigger threat then outsiders.
also vulnerability assessment is about things that do exist on the network... PT is about real life exploitation (was suppose to be)
If a team or group of people can't penetrate a vulnerability identified then that doesn't limit the danger's of vulnerability that just shows the limitation at the teams end.
hope this can help.Website :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Blog :
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-
06-20-2011, 06:40 PM #3Garage Hyper Addict


- Join Date
- Jul 2010
- Location
- irc.freenode.net #g4h
- Posts
- 639
- Thanks
- 140
- Thanked 270 Times in 109 Posts
The points here might help.
[*] To follow the path: look to the master, follow the master, walk with the master, see through the master,
------> become the master!!! <------
[*] Everyone has a will to WIN but very few have the will to prepare to WIN
[*] Invest yourself in everything you do, there's fun in being serious
-
06-20-2011, 08:51 PM #4Administrator
- Join Date
- Jul 2010
- Location
- Above Sea level
- Posts
- 163
- Blog Entries
- 1
- Thanks
- 8
- Thanked 71 Times in 31 Posts
u should tel them really whats the insider threats can be also recent attacks happend on RSA ,google hackers targeted internal employees and then those impacts were high i think evry 1 knows that its like i have Firewall on my perimiter so it doesnt mean they r secure .
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Hire a Hacker by the Night and Hire a Chief Security Officer (CSO) by the Day.
-
06-21-2011, 08:01 PM #5Garage Newcomer
- Join Date
- Jun 2011
- Posts
- 2
- Thanks
- 1
- Thanked 1 Time in 1 Post
I think Operation Aurora ( Google China hack) is the best example .. some good resources -- > http://www.cert.org/insider_threat/
-
06-23-2011, 10:54 PM #6Garage Newcomer
- Join Date
- Jul 2010
- Location
- Pune
- Posts
- 34
- Thanks
- 7
- Thanked 1 Time in 1 Post
Pentest Vs Vulnerability Asssesment
One of the best article I ever read...
Good comparison!
http://www.tns.com/PenTestvsVScan.aspI will find a way or make one...



LinkBack URL
About LinkBacks



Reply With Quote
any ms08-067 alternative for w7/8?
Yesterday, 09:44 AM in Hacking for Beginners