Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests and 3 members online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
EH-Net
News Items and General Discussion About EH-Net
Pen-Testing Reporting
Ethical Hacker Community Forums
January 09, 2009, 07:55:52 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf.
www.chicagocon.com
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
EH-Net
>
News Items and General Discussion About EH-Net
(Moderator:
don
) >
Pen-Testing Reporting
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Pen-Testing Reporting (Read 3237 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Full Member
Offline
Posts: 224
Pen-Testing Reporting
«
on:
May 11, 2006, 01:53:14 PM »
What type of reports or teamplates do you all use for pen-testing? We just completed ours for a lawfirm and I am unsure how I am going to report the results. Any and all suggestions are welcome. Thanks!
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Oyle
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: Pen-Testing Reporting
«
Reply #1 on:
May 14, 2006, 11:29:46 AM »
As part of my CCE studies, they give you a sample of a "Chain of Custody" form. Maybe you could change it and use it for pen-testing. It's in Word, don't think it has any kind of copyright or anything. If you want I could send it to you for you to look at it.
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
Dengar13
Full Member
Offline
Posts: 224
Re: Pen-Testing Reporting
«
Reply #2 on:
May 14, 2006, 12:57:18 PM »
Could you? That would be great. Thanks man!
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
tmartin
Recruiters
Newbie
Offline
Posts: 46
Re: Pen-Testing Reporting
«
Reply #3 on:
May 17, 2006, 09:23:09 PM »
Here's the info that I find useful:
Risk: H/M/L
Severity: H/M/L
Probability: H/M/L
Remediation effort:H/M/L
Issue: (describe the problem: vulnerability, Host/IP, how it can be exploited
Affected: (identify the affected devices: PIX firewall, PrintServer1, etc.)
Business impact: (like loss of operation services, theft of bandwidth, etc.)
Remediation (How to fix it)
Of course you want an overall summary and a description of the methods used and the IPs/DIDs/etc. that were tested.
Logged
Dengar13
Full Member
Offline
Posts: 224
Re: Pen-Testing Reporting
«
Reply #4 on:
May 18, 2006, 03:40:44 AM »
Thanks! This is a good standardized list of things for these types of scans/assessments.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Kev
Guest
Re: Pen-Testing Reporting
«
Reply #5 on:
June 24, 2006, 04:24:21 PM »
The sans site has some basic templates in their reading room if my memory is correct. Also, I like to include a print out from Nessus and then do some pretty graphs with excel. Seems like people like to see a lot of pages with graphs and print outs even if they have no idea of what it means. The key is to include a final page summary that is easier to follow. Put it all in a nice binder and they will feel they got their moneys worth.
Logged
Dengar13
Full Member
Offline
Posts: 224
Re: Pen-Testing Reporting
«
Reply #6 on:
June 24, 2006, 08:20:16 PM »
The graphs and printouts are the "executive" reporting righ? LOL! It must make them feel special to see all of those pretty charts. That is a good point about putting it in a binder, more concise that way.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Other
: Windows 7 Beta Available Tomorrow
(7) by
NickFnord
Wireless
: WEP cracking, how to ping router?
(2) by
duffman984
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(2) by
rforsythe
Book Reviews
: Need a book suggestion!
(5) by
unicityd
OSCP - Offensive Security Certified Professional
: Offensive Security Releases Sample Pen Testing Report
(2) by
Chan
Web Applications
: Determine URL from IP address
(3) by
scottr
Malware
: uninstall trend mciro officescan clients
(2) by
Hack_80
Other
: openSUSE 11.1 Released
(0) by
don
Other
: Insanity?
(5) by
jason
Other
: Fedora Hits the 10 Spot
(0) by
don
Other
: FreeBSD 7.1 Released
(0) by
don
OSCP - Offensive Security Certified Professional
: Next Up OSCP101 v2.0
(39) by
don
Tools
: Core Impact Essentials
(0) by
sgt_mjc
News from the Outside World
: Google branching out a little further...
(3) by
jason
Physical Security
: Magnetic stripe card spoofing
(5) by
jason
Gates
: Oracle version module for metasploit
(3) by
RoleReversal
Malware
: THe website is Evil but what to do??
(3) by
NickFnord
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.