Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
BA Computer Science TESC
#14
Yeah I am the guy that gets the pen test report at my company. We have pen tests yearly and enterprise security wants to go to quarterly but we just don't have time to remediate all the items found on that schedule. Security compliance is an annoyance to most project managers who have other projects they are behind on anyway.

The pen test people start out by doing footprinting. They will determine as much info as possible about the company via whois, google and your own site map and any bios they find on the site. Then they click around your pages, check the html source for telltale signs of technology. You can pretty easily determine if the site or web app was built using java struts, asp.net v 1-4, jsf, coldfusion, php etc or some content management system. If they determine that it was a content management system that is outdated and they go to that content mgmt system's site and find out that the latest version fixed a horrible security hole, they will attempt to exploit that hole.

Things they look for is the ability to cause a denial of service attack on the site, or to deface the site, or to craft a url to send to someone in an email that makes it look like its coming from your trusted site but once you click the url you go to their hacker site. That is a blind redirect.

They come up with all this and put it into a nicely formatted pen test starting with an executive summary and listing the items in order of importance. They describe the problem, the risk, how to reproduce it and sometimes suggest a way to mitigate that risk.

Then someone like me reads the pen test, determines the level of effort to fix the items on the list and sends that to management. Management then bargains with enterprise security on resource allocation.

Finally I get assigned a project to fix the ones under my umbrella and I may have to work with other teams to help them fix their issues.

The pen testers use a toolkit to do this. The same toolkit that hackers use in most cases. These toolkits are free and well documented. The pen testers do need to know how to manage networks, IIS servers, mail servers etc because their goal if possible is to hack into your server and do something bad to it or document that it could be done.

To me the pen tester is basically a network technician with specialized skills. The write no code at all but have to open up tcp dumps, watch traffic, analyze http headers so they need to know how distributed processing works, the ssl handshake, http post protocol etc.

Yes the CEH certification is for professional pen testers. The CISA is a certified auditor and CISSP is a general security certification. I am one of the few CISSPs that has a software development background that I know. Most are either internal IT security people from a networking background or security consultants from RSA etc traveling the country selling their products.
BSBA CIS from TESC, BA Natural Science/Math from TESC
MBA Applied Computer Science from NCU
Enrolled at NCU in the PhD Applied Computer Science


Messages In This Thread
BA Computer Science TESC - by skyfall123 - 03-17-2011, 05:27 AM
BA Computer Science TESC - by ryoder - 03-17-2011, 05:52 AM
BA Computer Science TESC - by SandraNC - 03-17-2011, 01:03 PM
BA Computer Science TESC - by skyfall123 - 03-17-2011, 08:46 PM
BA Computer Science TESC - by SandraNC - 03-18-2011, 06:05 AM
BA Computer Science TESC - by skyfall123 - 03-18-2011, 06:46 AM
BA Computer Science TESC - by SandraNC - 03-18-2011, 08:16 AM
BA Computer Science TESC - by skyfall123 - 03-19-2011, 04:17 AM
BA Computer Science TESC - by ryoder - 03-19-2011, 06:29 AM
BA Computer Science TESC - by skyfall123 - 03-19-2011, 07:58 AM
BA Computer Science TESC - by ryoder - 03-19-2011, 10:01 AM
BA Computer Science TESC - by SandraNC - 03-19-2011, 07:19 PM
BA Computer Science TESC - by skyfall123 - 03-20-2011, 05:40 AM
BA Computer Science TESC - by ryoder - 03-20-2011, 06:16 AM
BA Computer Science TESC - by skyfall123 - 03-21-2011, 05:45 AM
BA Computer Science TESC - by skyfall123 - 04-02-2011, 08:41 AM
BA Computer Science TESC - by jmed - 04-02-2011, 01:49 PM
BA Computer Science TESC - by skyfall123 - 04-02-2011, 04:01 PM
BA Computer Science TESC - by ryoder - 04-02-2011, 06:31 PM
BA Computer Science TESC - by beargins - 10-23-2011, 07:39 AM
BA Computer Science TESC - by ryoder - 10-23-2011, 09:47 AM
BA Computer Science TESC - by skyfall123 - 10-23-2011, 11:45 AM
BA Computer Science TESC - by beargins - 10-23-2011, 03:19 PM
BA Computer Science TESC - by ryoder - 10-23-2011, 05:34 PM

Possibly Related Threads...
Thread Author Replies Views Last Post
  TESU Computer Concepts CIS-107 sambeaux 3 2,316 09-01-2018, 12:23 AM
Last Post: Merlin
  TESU Help planning exams for ASNSM in Computer Science theveganmaker 3 1,900 07-27-2018, 10:52 AM
Last Post: theveganmaker
  First Post - TESC Academic Evaluation Questions npk32 34 6,988 07-18-2018, 01:03 PM
Last Post: npk32
  TESU - BA in Computer Science Gone? MrBossmanJr 5 2,097 07-10-2018, 03:56 PM
Last Post: MNomadic
  TESU BA Computer Science nyvrem 5 2,937 06-30-2018, 07:46 PM
Last Post: bjcheung77
  TESU ASNSM/BALS w Computer Science thewupk 1 1,431 05-05-2018, 03:06 PM
Last Post: davewill
  TESU ASNSM in Computer Science (Math/ALEKS) question AwardTour 7 2,854 05-03-2018, 07:03 AM
Last Post: Merlin
Sad TESU has stopped offering a BA in Computer Science? johnw 14 4,043 04-24-2018, 02:06 AM
Last Post: bluebooger
  COSC Science Lab -- ed4credit accepted? stampbuyme 7 2,153 04-18-2018, 06:33 PM
Last Post: dfrecore
  COSC Science Lab Requirement ? stampbuyme 7 3,041 04-10-2018, 02:05 AM
Last Post: videogamesrock

Forum Jump:


Users browsing this thread: 4 Guest(s)