|
EH-Net
|
|
May 22, 2013, 06:47:20 PM
|
Show Posts
|
|
Pages: 1 [2] 3 4 ... 24
|
|
22
|
Ethical Hacking Discussions and Related Certifications / Compliance, Regulations & Standards / Re: Approved Scanning Vendor - PCI
|
on: January 14, 2013, 10:20:29 AM
|
|
External scan reports must be generated through an ASV company. An important distinction is that the person running the scan does not have to be an employee of the ASV company. You can manage your own scans through the ASV's portal. The report will contain a page that has the ASV number associated with the company that performed the scan. If you're ever audited or have to submit your report to your acquiring bank, the auditor/bank will be looking for that number on the report. Basically, you cannot scan your own perimeter with your own copy of Nessus, generate a report, and say you're compliant. It must be done by an ASV company.
Internal scan reports can be done by anyone knowledgeable in Vulnerability Scanning/Management. It should not be managed by a person responsible for maintaining the systems being scanned, though (separation of duties).
Hope that helps.
|
|
|
|
|
23
|
Features / Opinions / Re: Disney and RFID bracelets.....
|
on: January 09, 2013, 03:30:50 PM
|
|
I don't have any further information about how Disney plans to implement this, but fraud within the parks would be very easy to detect. They're using RFID to track visitors. Each RFID chip will be uniquely identifiable, so they would be able to detect you pulling Fast Passes at the Magic Kingdom while simultaneously shopping at Downtown Disney.
The question is, will they implement fraud detection in the system? If the fraud becomes rampant enough that they're losing money, they will.
|
|
|
|
|
24
|
Ethical Hacking Discussions and Related Certifications / Other / Re: Where are you from?
|
on: January 07, 2013, 04:13:35 PM
|
For me in Canada, there's currently 2 feet of snow outside. Funny thing is if you accumulate all the snow that's fallen my entire life in Mississippi, it probably would just barely be 2 feet of snow. On an unrelated but uncanny note, I'm in Toronto with a foot or so of snow on the ground at the moment.
|
|
|
|
|
26
|
Resources / Career Central / Re: Question about penetration testing specialties
|
on: January 02, 2013, 10:38:17 AM
|
|
In my limited experience, the level of specialization required of a pentester is directly proportional to the size of the consulting firm you work for. The bigger the firm, the more specialization you can have. Smaller firms tend to need consultants that can do a lot of things well.
|
|
|
|
|
Loading...
|