Re: Core Impact Vs Manual Pen Test

From: Nick Selby (nick.selby@the451group.com)
Date: Thu Aug 31 2006 - 15:37:13 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I don't think it's either/or - not sure if this is useful to you
because it doesn't give you the 'What's core like' answer but our
company thinks that more and more companies are buying one or both
Core and Canvas for basic tests and getting a better understanding of
how things are working, then hiring experts for more specific tests,
or to ensure that while relatively novice pentesters (in the NOC) can
run standard point and shoot tests, professionals come in to do the
heavy lifting. Not rocket science, but a trend, we think!

http://blogs.the451group.com/opensource/2006/08/25/in-the-pen-test-community-open-source-permeates-upwards-and-a-trend-emerges/

HTH
Nick

jackal_pf0@lycos.com wrote:
> Dear Members,
>
> I've been doing Pen test for a quite while. I have used both Open
source and Commercial tools for the activity. Now because of automated
tools such as core Impact, Canvas, Qualys most of the clients are coming
up with the Question of Whether to go fo Core Impact or hire some
consultants to do the activity. These clients are not worried bout
paying huge money to buy these tools.
>
> Since I have not used Core Impact, I cant figure out the differences. I
believe you guys can help me out.
>
> Any comments appreciated.
>
> Regds,
>
> J
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Need to secure your web apps?
> Cenzic Hailstorm finds vulnerabilities fast.
> Click the link to buy it, try it or download Hailstorm for FREE.
> http://www.cenzic.com/products_services/download_hailstorm.php
> ------------------------------------------------------------------------
>

- --
Nick Selby
Senior Analyst, Enterprise Security
The 451 Group - Analyzing the business of IT innovation
52 Broad St, 2nd Floor Boston, MA 02109
t 617 261 0533 m 347 675 8295 f 617 261 0688
nick.selby@the451group.com | http://www.the451group.com

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFE9zpp1x+5mkiqtFgRAtzmAJ47gCoYWOBS1CtpNpV6GpOcKj4MxwCfTp38
1K+ISZzP29VLANixeJRZsZY=
=zM07
-----END PGP SIGNATURE-----

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:52 EDT