In Brief

Penetration Testing: Shortcuts to a Good Test

Penetration Testing: Shortcuts to a Good Test

By Michael Fitzgerald

July 01, 2006CSO

Giving consultants three days to hack a system is no way to replicate what a hacker might do, argues Peiter "Mudge" Zatko, a well-known hacker and consultant who is now a division scientist at BBN Technologies.

"Somebody on the outside can take as much time as they wanttheyll eventually stumble across something," he says.

Companies cant pay consultants to hack at will for months on end. But they can open up things like the configuration files from the routers, the firewall rules and the network maps to give the consultant a head start. It will also help the consultant understand how a company views security in light of its business.

"It will save you time and money," says Zatko. In fact, he says that if the consultants find things in this document phase, the company can fix them, and then let the penetration testing begin.

Zatko says companies should combine external pen tests with internal ones, to see what might already be compromised inside the perimeterinformation that wont appear in a pen test.

M.F.

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors