Penetration Testing mailing list archives
Re: Pentesting tool - Commercial
From: Pete Herzog <lists () isecom org>
Date: Tue, 04 Mar 2008 18:36:54 +0100
Hi, Ivan Arce wrote: <snip>
Going back to the original comments about CORE IMPACT and the 'count of exploits' I'd like point out just that throwing numbers without qualifying the measurement criteria and the relevance of the methodology is not a very serious assessment of a product's capabilities, its suitability for a given use or the value it may provide to a security professional.
I'd like to add as a person not actually selling products or having any commercial ties to any software tool maker that Ivan is correct here. There are so many important variables to how a tool should work that judging on numbers alone of something that has no clear standard for how it should be counted is just ignorant.
-pete. www.isecom.org ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- Re: Pentesting tool - Commercial p1g (Mar 03)
- <Possible follow-ups>
- Re: Pentesting tool - Commercial Ivan Arce (Mar 03)
- Re: Pentesting tool - Commercial Andre Gironda (Mar 04)
- Re: Pentesting tool - Commercial Trygve Aasheim (Mar 04)
- Re: Pentesting tool - Commercial Andre Gironda (Mar 04)
- Re: Pentesting tool - Commercial Trygve Aasheim (Mar 04)
- Re: Pentesting tool - Commercial Andre Gironda (Mar 04)
- AW: Pentesting tool - Commercial puppe (Mar 05)
- Re: Pentesting tool - Commercial Andre Gironda (Mar 04)
- RE: Pentesting tool - Commercial Clint P. Garrison (Mar 05)