Perspectives on Penetration Testing
Paul Midian · Computer Fraud & Security · 2002
This article discusses some obvious findings revealed by penetration testing . I run the security testing services team for a risk management and security consultancy and I have been involved with ‘pure’ penetration testing for four years now; prior to that I worked on ITSEC evaluations (which also contained an element of penetration testing). Well, someone has too! Actually, what the ITSEC scheme gave me is a good understanding of software vulnerabilities — why they occur, how they can be found, how they can be patched, etc. This has proved very useful on penetration testing engagements as it has given me an understanding of why software is insecure. At a code level, software can be vulnerable for many reasons, i.e. the ubiquitous buffer overrun, executing as root, not handling error conditions, etc. However, at a system level the reasons are much simpler. This is what I will be discussing in this article.