<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Penetration Testing</title>
	<atom:link href="http://www.cigital.com/justice-league-blog/2007/02/28/penetration-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/justice-league-blog/2007/02/28/penetration-testing/</link>
	<description></description>
	<lastBuildDate>Wed, 30 Nov 2011 15:50:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Roshen Chandran</title>
		<link>http://www.cigital.com/justice-league-blog/2007/02/28/penetration-testing/#comment-12</link>
		<dc:creator>Roshen Chandran</dc:creator>
		<pubDate>Fri, 23 Mar 2007 08:29:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/blog/2007/02/28/penetration-testing/#comment-12</guid>
		<description>Interesting post, Pravir. Yes, taking a business risk approach to identifying vulnerabilities is more effective than banging a set of exploits blindly at an application in penetration tests.

However, the automated tools we have seen do not &quot;discover&quot; business risks during &lt;a href=&quot;http://www.plynt.com/resources/learn/tools/what_cant_a_scanner_find_1/&quot; rel=&quot;nofollow&quot;&gt;penetration tests&lt;/a&gt;. So, giving automated tools to a QA engineer and training them in feeding the right values alone will not solve the problem.</description>
		<content:encoded><![CDATA[<p>Interesting post, Pravir. Yes, taking a business risk approach to identifying vulnerabilities is more effective than banging a set of exploits blindly at an application in penetration tests.</p>
<p>However, the automated tools we have seen do not &#8220;discover&#8221; business risks during <a href="http://www.plynt.com/resources/learn/tools/what_cant_a_scanner_find_1/" rel="nofollow">penetration tests</a>. So, giving automated tools to a QA engineer and training them in feeding the right values alone will not solve the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pravir</title>
		<link>http://www.cigital.com/justice-league-blog/2007/02/28/penetration-testing/#comment-11</link>
		<dc:creator>pravir</dc:creator>
		<pubDate>Fri, 02 Mar 2007 04:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/blog/2007/02/28/penetration-testing/#comment-11</guid>
		<description>Well, PCI&#039;s Requirement #11.3 is the one that specifically calls out the need to pen-test the application. If you check out the &lt;a href=&quot;http://www.pcisecuritystandards.org/pdfs/pci_audit_procedures_v1-1.pdf&quot; rel=&quot;nofollow&quot;&gt;audit procedures for PCI&lt;/a&gt; the instructions for auditing against 11.3 basically call out 1) make sure they&#039;re being done, and 2) make sure that the bad stuff that was identified is getting fixed. So, I don&#039;t think that procludes anyone from doing their pen-testing in-house (e.g. in the QA env).

And you&#039;re totally right about Jolt v. RedBull... but I gotta be honest, Cheetos were always first in my heart ;)</description>
		<content:encoded><![CDATA[<p>Well, PCI&#8217;s Requirement #11.3 is the one that specifically calls out the need to pen-test the application. If you check out the <a href="http://www.pcisecuritystandards.org/pdfs/pci_audit_procedures_v1-1.pdf" rel="nofollow">audit procedures for PCI</a> the instructions for auditing against 11.3 basically call out 1) make sure they&#8217;re being done, and 2) make sure that the bad stuff that was identified is getting fixed. So, I don&#8217;t think that procludes anyone from doing their pen-testing in-house (e.g. in the QA env).</p>
<p>And you&#8217;re totally right about Jolt v. RedBull&#8230; but I gotta be honest, Cheetos were always first in my heart <img src='http://www.cigital.com/justice-league-blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zach</title>
		<link>http://www.cigital.com/justice-league-blog/2007/02/28/penetration-testing/#comment-10</link>
		<dc:creator>Zach</dc:creator>
		<pubDate>Thu, 01 Mar 2007 21:22:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/blog/2007/02/28/penetration-testing/#comment-10</guid>
		<description>What about pen-testing with regard to PCI? Surely that nudges QA aside. Think we&#039;ll still be stuck, then, with the, uh, &quot;traditional&quot; penetration test?


Oh, and Red Bull and Cheetos?

If you&#039;re talking old school, it&#039;d be more along the lines of Jolt and Doritos (or ramen, if you ever read the &quot;Cyberpunk Handbook&quot;).</description>
		<content:encoded><![CDATA[<p>What about pen-testing with regard to PCI? Surely that nudges QA aside. Think we&#8217;ll still be stuck, then, with the, uh, &#8220;traditional&#8221; penetration test?</p>
<p>Oh, and Red Bull and Cheetos?</p>
<p>If you&#8217;re talking old school, it&#8217;d be more along the lines of Jolt and Doritos (or ramen, if you ever read the &#8220;Cyberpunk Handbook&#8221;).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

