PDA

View Full Version : [ubuntu] how to do a successfull pen tes?


noobl33t
July 18th, 2009, 01:27 AM
What doi u need to know about a system before you attack it?

lisati
July 18th, 2009, 01:31 AM
How much trouble you are likely to cause or be in if you get caught is a big consideration. It's usually a good idea to hold off until you're sure that the person whose system it is has given their blessing.

doas777
July 18th, 2009, 01:38 AM
definitely. get signatures on paper.

as for casing the joint, what kinda system are we talking? what attack surface does it have? what is your goal, and what are the ground rules for your test scenario?

koenn
July 19th, 2009, 09:12 AM
how to do a successfull pen tes?

What doi u need to know about a system before you attack it?

nothing. extracting info from the system is part of the test.

The Tronyx
July 19th, 2009, 09:25 AM
I hope this doesn't come across as rude, but I think if you are asking that question, it is very likely that you are not prepared to perform a successful pen test.

There a lot of factors that come into play such as consent from the managers of the network/machines in question and consent from the highest authority at the institution to be audited. If the test is going to be done remotely, to do everything 100% by the book, you will also need consent from your ISP and possibly any transient carriers depending on the scope of the test.

koenn
July 19th, 2009, 09:57 AM
I hope this doesn't come across as rude, but I think if you are asking that question, it is very likely that you are not prepared to perform a successful pen test.

There a lot of factors that come into play such as consent from the managers of the network/machines in question and consent from the highest authority at the institution to be audited. If the test is going to be done remotely, to do everything 100% by the book, you will also need consent from your ISP and possibly any transient carriers depending on the scope of the test.

I got the feeling this l33t noob isn't really talking about a formal penetration test :)

doas777
July 20th, 2009, 12:16 PM
do you ever get the feeling that sometimes people post impossible questions and never log back in, just to troll us?

grayn0de
July 20th, 2009, 12:29 PM
do you ever get the feeling that sometimes people post impossible questions and never log back in, just to troll us?

I get the feeling it's working. lol.

koenn
July 20th, 2009, 12:56 PM
do you ever get the feeling that sometimes people post impossible questions and never log back in, just to troll us?

my reading in this case is the kid wants step by step instructions on how to break in into a computer, or at least on how to collect information that could be helpful in such an attack, but he decided to call it "pen test" - either because he knows that otherwise, his thread would get closed, or because he's read somewhere that 'plz teach me how 2 hack' usually doesn't work.

An in stead of all the juicy tips and tricks he's expecting, he gets people talking about all sorts of paperwork and permissions and signatures ...

grayn0de
July 20th, 2009, 01:08 PM
my reading in this case is the kid wants step by step instructions on how to break in into a computer, or at least on how to collect information that could be helpful in such an attack, but he decided to call it "pen test" - either because he knows that otherwise, his thread would get closed, or because he's read somewhere that 'plz teach me how 2 hack' usually doesn't work.

An in stead of all the juicy tips and tricks he's expecting, he gets people talking about all sorts of paperwork and permissions and signatures ...

Sounds about right. The saddest thing is that they read/searched enough to know (kind of) what a pentest is, but stopped there before understanding or realizing that the information they need (maybe not want) is only a few more searches away.

I think it breaks the spirits of a lot of potential script kiddies when they realize what all it takes to perform a 'pen test'. :twisted:

noobl33t
July 27th, 2009, 12:33 AM
the computer i'm going to do a pen test or compromise is my own desktop and i have done that stupid nbstat thing it's stupid the only thing you can do is read some files!

I haven't log on in a wile because i had to go to my dad's house and he doesn't have internet!

I'm not going to to attack a ******* public or private network
that's ******* stupid!!!!!!!!!!

forestpiskie
July 27th, 2009, 01:30 PM
closed pending staff review - also duplicate thread.

http://ubuntuforums.org/showthread.php?t=1224039