Penetration Testing mailing list archives
RE: Pre-Scanning for Marketing
From: "Wray, Donald W" <Donald.Wray () HaverstickInc com>
Date: Wed, 11 Jan 2006 07:59:47 -0500
What I might do is contact, in person, an authorized officer of the organization, CIO, CISO, or CSO for example and offer a free preliminary scan and then set up a meeting to discuss the results and possible future work. But as you have said and many others that without permission it just is not ethical and could lead to no future work and maybe even something worse. Donald W. Wray, CISSP Donald.Wray () haverstickconsulting com ________________________________ From: Password Crackers, Inc. [mailto:pwcrack () pwcrack com] Sent: Tue 1/10/2006 9:43 PM To: pen-test () securityfocus com Subject: RE: Pre-Scanning for Marketing Please allow me to clarify that I have NOT done anything like this, I am not advocating it and have no plans to do so. I am aware that many prospects would potentially view this negatively. I mentioned in my original post that I understood this. Doing so could permanently impact someone's reputation. So, let's all understand that we are speaking about a hypothetical. I was interested to know if anyone had done so previously and what the reaction was. Clearly, it appears that other than a few free offers (I've made two of these in the past -- both with no response), this type of approach seems to be so negatively viewed that nobody would even attempt it. However, doesn't anyone else view this as something of a dilemma? As a group we are incapacitated from offering services to those who may need them (unless we do so inefficiently) even though certainly vulnerabilities are easily and efficiently identified. Unfortunately, the best analogy I can come up with is ambulance chasing lawyers -- who seem to be hated, so we probably don't want to follow their lead professionally. Has anyone effectively resolved this dilemma in their practice? Possibly that is how I should have phrased the original post. Bob Weiss Password Crackers, Inc. -----Original Message----- From: Clement Dupuis [mailto:cdupuis () cccure org] Sent: Tuesday, January 10, 2006 8:19 PM To: 'Password Crackers, Inc.' Subject: RE: Pre-Scanning for Marketing I would definitively say: DON'T What right do you have to test my environment without me asking. What differentiate you from any other cracker out there. You are just another one of them as far as I am concerned. Would you get any business this way? Probably some but very little and not from the client your really wish to build a long term relationship with. Thinks of the negative publicity and the fact that someone will take you to court for attempting to intruder on their communication means. Overall I would definitively NOT do it Clement -----Original Message----- From: Password Crackers, Inc. [mailto:pwcrack () pwcrack com] Sent: Tuesday, January 10, 2006 10:11 AM To: pen-test () securityfocus com Subject: Pre-Scanning for Marketing I am interested if anyone on the list has ever tested or implemented a marketing program that involved pre-scanning (wired or wireless) a prospect and then sending a letter or email describing potential vulnerabilities and offering assistance in closing these vulnerabilities. I have never done this because of the anticipated negative reaction, but I am curious as to what the outcome was if anyone else has done it. Single instances would be interesting, but I am more curious if anyone has implemented this in a more broad-based way and has positive and/or negative response rate statistics. Bob Weiss Password Crackers, Inc. ---------------------------------------------------------------------------- -- Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 ---------------------------------------------------------------------------- --- ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 ------------------------------------------------------------------------------- ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
Current thread:
- Re: Pre-Scanning for Marketing, (continued)
- Re: Pre-Scanning for Marketing Steve Friedl (Jan 11)
- Re: Pre-Scanning for Marketing alan (Jan 11)
- RE: Pre-Scanning for Marketing Nathan Einwechter (Jan 13)
- Re: Pre-Scanning for Marketing Kurt Seifried (Jan 15)
- RE: Pre-Scanning for Marketing Ken Kousky (Jan 17)
- Re: Pre-Scanning for Marketing Kurt Seifried (Jan 15)
- Re: Pre-Scanning for Marketing Kevin Johnson (Jan 14)
- RE: Pre-Scanning for Marketing Shenk, Jerry A (Jan 10)
- RE: Pre-Scanning for Marketing Ed Hudson (Jan 10)
- RE: Pre-Scanning for Marketing Stonewall (Jan 11)
- RE: Pre-Scanning for Marketing Password Crackers, Inc. (Jan 10)
- RE: Pre-Scanning for Marketing Wray, Donald W (Jan 11)
- RE: Pre-Scanning for Marketing David Ball (Jan 11)
- Re: Pre-Scanning for Marketing Robin Wood (Jan 11)
- RE: Pre-Scanning for Marketing Rapaille Maxime (Jan 11)
- Re: Pre-Scanning for Marketing Pete Herzog (Jan 11)
- RE: Pre-Scanning for Marketing Ron Yount (Jan 11)
- RE: Pre-Scanning for Marketing Maxim Kostioukov (Jan 12)
- RE: Pre-Scanning for Marketing Rapaille Maxime (Jan 12)
- RE: Pre-Scanning for Marketing Bergert, David (Jan 13)