<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security : True penetration testing?</title>
    <link>http://blog.clearnetsec.com</link>
    <atom:link type="application/rss+xml" rel="self" href="http://blog.clearnetsec.com/2008/05/04/true-penetration-testing?format=rss"/>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Comment on True penetration testing? by Andre Gironda</title>
      <description>&lt;p&gt;One day in the not-so-distant-future, exploits will reveal their true nature to the public &amp;#8211; that they are weapons of mass destruction.&lt;/p&gt;

&lt;p&gt;However, in this case &amp;#8211; I think it means &amp;#8216;overflow with A&amp;#8217;s&amp;#8217;, instead of &amp;#8220;Rapid Penetration Testing&amp;#8221; (c) CoreSec.  I&amp;#8217;m sure the PCI SSC will correct me, and later specify that only Core Impact used by a monkey qualifies (probably something as close to a real monkey as possible).&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&#8220;resources must be experienced penetration testers&#8221;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;What does that mean?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Tate, my man, you should know what this means.  The PCI SSC will specify the exact requirements for this once they figure out how to monetize it.  In other words, they need to figure out which certification vendor to get into bed with so that they can take a cut of the money.&lt;/p&gt;

&lt;p&gt;Also see: ASV + Qualys, Requirement 6.6 clarification + F5/Citrix, et al&lt;/p&gt;</description>
      <pubDate>Mon, 05 May 2008 04:15:13 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:b9a0fbba-3d40-4d9f-b371-352396887362</guid>
      <link>http://blog.clearnetsec.com/2008/05/04/true-penetration-testing#comment-64</link>
    </item>
    <item>
      <title>Comment on True penetration testing? by Tate Hansen</title>
      <description>&lt;p&gt;@Andre:  lol, my bad, you&#8217;re exactly right.  I was so wrapped up in the skills thing I forgot about the money thing.  Doh.  Feel free to deliver a sensibility roundhouse kick to my head anytime! :)&lt;/p&gt;</description>
      <pubDate>Mon, 05 May 2008 10:44:12 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:88f5304c-59f7-4e0d-a15c-d25b50457efa</guid>
      <link>http://blog.clearnetsec.com/2008/05/04/true-penetration-testing#comment-65</link>
    </item>
    <item>
      <title>Comment on True penetration testing? by LonerVamp</title>
      <description>&lt;p&gt;Just wait! They&amp;#8217;re going to get into bed with some Certified Ethical Hacker cert and that&amp;#8217;ll be the criteria!&lt;/p&gt;</description>
      <pubDate>Tue, 06 May 2008 14:26:16 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:056abf41-fd02-428f-b614-f30450a4505a</guid>
      <link>http://blog.clearnetsec.com/2008/05/04/true-penetration-testing#comment-66</link>
    </item>
  </channel>
</rss>
