Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 63 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow EH-Netarrow Special Eventsarrow [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing
EH-Net
May 25, 2012, 04:41:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: [Article]-Webcast: Modern Social Engineering - A Vital Component of Pen Testing  (Read 32340 times)
0 Members and 1 Guest are viewing this topic.
mmurray
Newbie
*
Offline Offline

Posts: 17



View Profile WWW
« Reply #30 on: March 16, 2009, 07:30:02 PM »

I'm late to the party, but I just couldn't help throw a few more thoughts into here.


Q: On a PenTest team, what is the best way to collaborate what you have found? I pentest and I have found that communication break down is one of the biggest problems within the PT team social context.
.....

#3 P0wned list. Mae a secured Wiki, have a shared doc..  or use collaboration frameworks to take notes for juicy intel and info. Review this list with the whole team daily for large projects and  every half day for smaller gigs.


For this function, I'd suggest checking out Dradis.  http://dradis.nomejortu.com/

It's a work in progress, but at Foreground we've already started testing it and we're thinking about putting it in production.


#4 Leverage traditional PM skills

Since traditional pen-tests aren't highly complex projects, you don't need a full-scale PM.  Here's where a student intern can really help out - I'm a big fan of finding someone in a local college who is looking to become a project manager... they can learn to PM, track data, track progress, etc.  And you get a resource appropriate for the level required. 

Depends on the project, of course. 
Logged

--
Mike Murray
MAD Security / The Hacker Academy

Email - mmurray@thehackeracademy.com
Phone - 773-360-0658
Twitter: http://www.twitter.com/mmurray
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.164 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.