RE: Penetration test report - your comments please?

From: railwayclubposseat_private
Date: Wed May 30 2001 - 13:03:09 PDT

  • Next message: Curt Wilson: "Re: Penetration test report - your comments please?"

    Zebra (http://www.zebra.org/) is great for testing protocols like IGMP (and 
    other routing protocols).
    
    pete [mailto:peteat_private] wrote:
    
    his pen test posted on Security Focuses' Pen-Test mailing list brings up
    the question of the testing of protocols as to the OSSTMM
    (http://www.osstmm.org) and the reliability of NMAP's protocol scanning. 
     As
    I apply the module "Port Scanning" the tasks for protocol identification 
    are
    a bit difficult to automate.  Of course, NMAP claims to do it but I
    consistantly get at least IGMP for most systems which I do have difficulty
    with accepting.  I use NMAP for many of the tasks in that section but hav
    been hesitant on the protocol testing.  Of course a bit of scripting will
    automate some but while I was a bit hesitant about NMAP's results I thought
    I would ask what others thought of this.
    
    Sincerely,
    -pete.
    
    
    Free, encrypted, secure Web-based email at www.hushmail.com
    
    
    IMPORTANT NOTICE:  If you are not using HushMail, this message could have been read easily by the many people who have access to your open personal email messages.
    Get your FREE, totally secure email address at http://www.hushmail.com.
    



    This archive was generated by hypermail 2b30 : Thu May 31 2001 - 08:34:20 PDT